6.1
CVE-2026-20466
- EPSS 0.17%
- Veröffentlicht 03.08.2026 02:05:17
- Zuletzt bearbeitet 03.08.2026 20:17:18
- CVE-Watchlists
- Unerledigt
In sec boot, there is a possible escalation of privilege due to a heap buffer overflow. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: AUTO00845351 (Note: For MT2737) / ALPS11072643 (Note: For MT6880, MT6890, MT6990); Issue ID: MSV-6929.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerMediaTek, Inc.
≫
Produkt
MediaTek chipset
Default Statusunaffected
Version
MT2737
Status
affected
Version
MT6880
Status
affected
Version
MT6890
Status
affected
Version
MT6990
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.062 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 6.1 | 0.9 | 5.2 |
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
https://www.mediatek.com/product-security-bulletin/August-2026