5.5

CVE-2023-32831

In wlan driver, there is a possible PIN crack due to use of insufficiently random values. This could lead to local information disclosure with no execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00325055; Issue ID: MSV-868.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mediatek ≫ Software Development Kit Version <= 7.6.7.1
   Mediatek ≫ Mt6890 Version -
   Mediatek ≫ Mt7612 Version -
   Mediatek ≫ Mt7613 Version -
   Mediatek ≫ Mt7615 Version -
   Mediatek ≫ Mt7622 Version -
   Mediatek ≫ Mt7626 Version -
   Mediatek ≫ Mt7629 Version -
   Mediatek ≫ Mt7915 Version -
   Mediatek ≫ Mt7916 Version -
   Mediatek ≫ Mt7981 Version -
   Mediatek ≫ Mt7986 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.074
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA-ADP 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-330 Use of Insufficiently Random Values

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

https://corp.mediatek.com/product-security-bulletin/January-2024
Vendor Advisory