6

CVE-2025-20658

In DA, there is a possible permission bypass due to a logic error. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09474894; Issue ID: MSV-2597.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Google ≫ Android Version 12.0 Update -
Google ≫ Android Version 13.0 Update -
Google ≫ Android Version 14.0
Google ≫ Android Version 15.0
Mediatek ≫ Mt2718 Version -
Mediatek ≫ Mt6781 Version -
Mediatek ≫ Mt6789 Version -
Mediatek ≫ Mt6835 Version -
Mediatek ≫ Mt6855 Version -
Mediatek ≫ Mt6878 Version -
Mediatek ≫ Mt6879 Version -
Mediatek ≫ Mt6886 Version -
Mediatek ≫ Mt6895 Version -
Mediatek ≫ Mt6897 Version -
Mediatek ≫ Mt6983 Version -
Mediatek ≫ Mt6985 Version -
Mediatek ≫ Mt6989 Version -
Mediatek ≫ Mt8196 Version -
Mediatek ≫ Mt8673 Version -
Mediatek ≫ Mt8676 Version -
Mediatek ≫ Mt8678 Version -
Mediatek ≫ Mt8781 Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.02
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 6 0.5 5.5
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://corp.mediatek.com/product-security-bulletin/April-2025
Vendor Advisory