6.8

CVE-2025-20656

In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09625423; Issue ID: MSV-3033.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linuxfoundation ≫ Yocto Version 4.0
Rdkcentral ≫ Rdk-b Version 2024q1
Google ≫ Android Version 12.0
Google ≫ Android Version 13.0
Google ≫ Android Version 14.0
Google ≫ Android Version 15.0
Openwrt ≫ Openwrt Version 21.02.0 Update -
Openwrt ≫ Openwrt Version 23.05
Mediatek ≫ Mt6781 Version -
Mediatek ≫ Mt6789 Version -
Mediatek ≫ Mt6835 Version -
Mediatek ≫ Mt6855 Version -
Mediatek ≫ Mt6878 Version -
Mediatek ≫ Mt6879 Version -
Mediatek ≫ Mt6886 Version -
Mediatek ≫ Mt6895 Version -
Mediatek ≫ Mt6897 Version -
Mediatek ≫ Mt6983 Version -
Mediatek ≫ Mt6985 Version -
Mediatek ≫ Mt6989 Version -
Mediatek ≫ Mt6990 Version -
Mediatek ≫ Mt8196 Version -
Mediatek ≫ Mt8370 Version -
Mediatek ≫ Mt8390 Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.029
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 6.8 0.9 5.9
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://corp.mediatek.com/product-security-bulletin/April-2025
Vendor Advisory