6.8
CVE-2022-20034
- EPSS 0.02%
- Veröffentlicht 09.02.2022 23:15:17
- Zuletzt bearbeitet 21.11.2024 06:41:59
- Quelle security@mediatek.com
- CVE-Watchlists
- Unerledigt
In Preloader XFLASH, there is a possible escalation of privilege due to an improper certificate validation. This could lead to local escalation of privilege for an attacker who has physical access to the device with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06160806.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Google ≫ Android Version11.0
Mediatek ≫ Mt6580 Version-
Mediatek ≫ Mt6735 Version-
Mediatek ≫ Mt6739 Version-
Mediatek ≫ Mt6761 Version-
Mediatek ≫ Mt6763 Version-
Mediatek ≫ Mt6765 Version-
Mediatek ≫ Mt6768 Version-
Mediatek ≫ Mt6769 Version-
Mediatek ≫ Mt6771 Version-
Mediatek ≫ Mt6779 Version-
Mediatek ≫ Mt6781 Version-
Mediatek ≫ Mt6785 Version-
Mediatek ≫ Mt6799 Version-
Mediatek ≫ Mt6833 Version-
Mediatek ≫ Mt6853 Version-
Mediatek ≫ Mt6873 Version-
Mediatek ≫ Mt6875 Version-
Mediatek ≫ Mt6877 Version-
Mediatek ≫ Mt6885 Version-
Mediatek ≫ Mt6891 Version-
Mediatek ≫ Mt6893 Version-
Mediatek ≫ Mt6735 Version-
Mediatek ≫ Mt6739 Version-
Mediatek ≫ Mt6761 Version-
Mediatek ≫ Mt6763 Version-
Mediatek ≫ Mt6765 Version-
Mediatek ≫ Mt6768 Version-
Mediatek ≫ Mt6769 Version-
Mediatek ≫ Mt6771 Version-
Mediatek ≫ Mt6779 Version-
Mediatek ≫ Mt6781 Version-
Mediatek ≫ Mt6785 Version-
Mediatek ≫ Mt6799 Version-
Mediatek ≫ Mt6833 Version-
Mediatek ≫ Mt6853 Version-
Mediatek ≫ Mt6873 Version-
Mediatek ≫ Mt6875 Version-
Mediatek ≫ Mt6877 Version-
Mediatek ≫ Mt6885 Version-
Mediatek ≫ Mt6891 Version-
Mediatek ≫ Mt6893 Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.02% | 0.055 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 0.9 | 5.9 |
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
CWE-295 Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.