Vulnerability Description
In Wi-Fi driver, there is a possible system crash due to null pointer dereference. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: GN20220720014; Issue ID: GN20220720014.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mediatek | Mt5221 Firmware | 7.6.6.1 |
| Mediatek | Mt5221 | - |
| Mediatek | Mt7603 Firmware | 7.6.6.1 |
| Mediatek | Mt7603 | - |
| Mediatek | Mt7613 Firmware | 7.6.6.1 |
| Mediatek | Mt7613 | - |
| Mediatek | Mt7615 Firmware | 7.6.6.1 |
| Mediatek | Mt7615 | - |
| Mediatek | Mt7622 Firmware | 7.6.6.1 |
| Mediatek | Mt7622 | - |
| Mediatek | Mt7628 Firmware | 7.6.6.1 |
| Mediatek | Mt7628 | - |
| Mediatek | Mt7629 Firmware | 7.6.6.1 |
| Mediatek | Mt7629 | - |
| Mediatek | Mt7668 Firmware | 7.6.6.1 |
| Mediatek | Mt7668 | - |
| Mediatek | Mt7902 Firmware | 7.6.6.1 |
| Mediatek | Mt7902 | - |
| Mediatek | Mt7915 Firmware | 7.6.6.1 |
| Mediatek | Mt7915 | - |
Related Weaknesses (CWE)
References
- https://corp.mediatek.com/product-security-bulletin/February-2023Vendor Advisory
- https://corp.mediatek.com/product-security-bulletin/February-2023Vendor Advisory
FAQ
What is CVE-2022-32663?
CVE-2022-32663 is a vulnerability with a CVSS score of 7.5 (HIGH). In Wi-Fi driver, there is a possible system crash due to null pointer dereference. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not n...
How severe is CVE-2022-32663?
CVE-2022-32663 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-32663?
Check the references section above for vendor advisories and patch information. Affected products include: Mediatek Mt5221 Firmware, Mediatek Mt5221, Mediatek Mt7603 Firmware, Mediatek Mt7603, Mediatek Mt7613 Firmware.