7.2

CVE-2021-0904

In SRAMROM, there is a possible permission bypass due to an insecure permission setting. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06076938; Issue ID: ALPS06076938.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GoogleAndroid Version8.1
   MediatekMt6771 Version-
   MediatekMt8183 Version-
   MediatekMt8385 Version-
   MediatekMt8788 Version-
GoogleAndroid Version9.0
   MediatekMt6771 Version-
   MediatekMt8183 Version-
   MediatekMt8385 Version-
   MediatekMt8788 Version-
GoogleAndroid Version10.0
   MediatekMt6771 Version-
   MediatekMt8183 Version-
   MediatekMt8385 Version-
   MediatekMt8788 Version-
GoogleAndroid Version11.0
   MediatekMt6771 Version-
   MediatekMt8183 Version-
   MediatekMt8385 Version-
   MediatekMt8788 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.01% 0.009
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-732 Incorrect Permission Assignment for Critical Resource

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.