Vulnerability Description
In CDMA PPP protocol, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: MOLY01068234; Issue ID: ALPS08010003.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mediatek | Lr11 | - |
| Mediatek | Lr12A | - |
| Mediatek | Lr13 | - |
| Mediatek | Nr15 | - |
| Mediatek | Nr16 | - |
| Mediatek | Nr17 | - |
| Mediatek | Mt2731 | - |
| Mediatek | Mt6570 | - |
| Mediatek | Mt6580 | - |
| Mediatek | Mt6595 | - |
| Mediatek | Mt6732 | - |
| Mediatek | Mt6735 | - |
| Mediatek | Mt6737 | - |
| Mediatek | Mt6737M | - |
| Mediatek | Mt6738 | - |
| Mediatek | Mt6739 | - |
| Mediatek | Mt6750 | - |
| Mediatek | Mt6750S | - |
| Mediatek | Mt6752 | - |
| Mediatek | Mt6753 | - |
Related Weaknesses (CWE)
References
- https://corp.mediatek.com/product-security-bulletin/October-2023Vendor Advisory
- https://corp.mediatek.com/product-security-bulletin/October-2023Vendor Advisory
FAQ
What is CVE-2023-20819?
CVE-2023-20819 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In CDMA PPP protocol, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privilege needed. User inter...
How severe is CVE-2023-20819?
CVE-2023-20819 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-20819?
Check the references section above for vendor advisories and patch information. Affected products include: Mediatek Lr11, Mediatek Lr12A, Mediatek Lr13, Mediatek Nr15, Mediatek Nr16.