9.8

CVE-2020-13840

An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). Code execution can occur via an MTK AT command handler buffer overflow. The LG ID is LVE-SMP-200008 (June 2020).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GoogleAndroid Version7.2
   LgCv1 Version-
   LgCv1s Version-
   LgCv3 Version-
   LgCv5 Version-
   LgCv7 Version-
   LgCv7as Version-
   LgDh10 Version-
   LgDh15 Version-
   LgDh30 Version-
   LgDh35 Version-
   LgDh40 Version-
   LgDh5 Version-
   LgDh50 Version-
   LgG6 Version-
   LgG7 Version-
   LgG8 Version-
   LgK20 Version-
   LgK30 Version-
   LgK40 Version-
   LgK50 Version-
   LgQ6 Version-
   LgQ60 Version-
   LgQ70 Version-
   LgQ8 Version-
   LgV20 Version-
   LgV30 Version-
   LgV35 Version-
   LgV40 Version-
   LgV50 Version-
   LgV60 Version-
   LgX Cam Version-
   LgX300 Version-
   LgX400 Version-
   LgX500 Version-
GoogleAndroid Version8.0
   LgCv1 Version-
   LgCv1s Version-
   LgCv3 Version-
   LgCv5 Version-
   LgCv7 Version-
   LgCv7as Version-
   LgDh10 Version-
   LgDh15 Version-
   LgDh30 Version-
   LgDh35 Version-
   LgDh40 Version-
   LgDh5 Version-
   LgDh50 Version-
   LgG6 Version-
   LgG7 Version-
   LgG8 Version-
   LgK20 Version-
   LgK30 Version-
   LgK40 Version-
   LgK50 Version-
   LgQ6 Version-
   LgQ60 Version-
   LgQ70 Version-
   LgQ8 Version-
   LgV20 Version-
   LgV30 Version-
   LgV35 Version-
   LgV40 Version-
   LgV50 Version-
   LgV60 Version-
   LgX Cam Version-
   LgX300 Version-
   LgX400 Version-
   LgX500 Version-
GoogleAndroid Version8.1
   LgCv1 Version-
   LgCv1s Version-
   LgCv3 Version-
   LgCv5 Version-
   LgCv7 Version-
   LgCv7as Version-
   LgDh10 Version-
   LgDh15 Version-
   LgDh30 Version-
   LgDh35 Version-
   LgDh40 Version-
   LgDh5 Version-
   LgDh50 Version-
   LgG6 Version-
   LgG7 Version-
   LgG8 Version-
   LgK20 Version-
   LgK30 Version-
   LgK40 Version-
   LgK50 Version-
   LgQ6 Version-
   LgQ60 Version-
   LgQ70 Version-
   LgQ8 Version-
   LgV20 Version-
   LgV30 Version-
   LgV35 Version-
   LgV40 Version-
   LgV50 Version-
   LgV60 Version-
   LgX Cam Version-
   LgX300 Version-
   LgX400 Version-
   LgX500 Version-
GoogleAndroid Version9.0
   LgCv1 Version-
   LgCv1s Version-
   LgCv3 Version-
   LgCv5 Version-
   LgCv7 Version-
   LgCv7as Version-
   LgDh10 Version-
   LgDh15 Version-
   LgDh30 Version-
   LgDh35 Version-
   LgDh40 Version-
   LgDh5 Version-
   LgDh50 Version-
   LgG6 Version-
   LgG7 Version-
   LgG8 Version-
   LgK20 Version-
   LgK30 Version-
   LgK40 Version-
   LgK50 Version-
   LgQ6 Version-
   LgQ60 Version-
   LgQ70 Version-
   LgQ8 Version-
   LgV20 Version-
   LgV30 Version-
   LgV35 Version-
   LgV40 Version-
   LgV50 Version-
   LgV60 Version-
   LgX Cam Version-
   LgX300 Version-
   LgX400 Version-
   LgX500 Version-
GoogleAndroid Version10.0
   LgCv1 Version-
   LgCv1s Version-
   LgCv3 Version-
   LgCv5 Version-
   LgCv7 Version-
   LgCv7as Version-
   LgDh10 Version-
   LgDh15 Version-
   LgDh30 Version-
   LgDh35 Version-
   LgDh40 Version-
   LgDh5 Version-
   LgDh50 Version-
   LgG6 Version-
   LgG7 Version-
   LgG8 Version-
   LgK20 Version-
   LgK30 Version-
   LgK40 Version-
   LgK50 Version-
   LgQ6 Version-
   LgQ60 Version-
   LgQ70 Version-
   LgQ8 Version-
   LgV20 Version-
   LgV30 Version-
   LgV35 Version-
   LgV40 Version-
   LgV50 Version-
   LgV60 Version-
   LgX Cam Version-
   LgX300 Version-
   LgX400 Version-
   LgX500 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.418
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.