8.4
CVE-2026-20524
- EPSS 0.13%
- Veröffentlicht 05.10.2026 01:39:52
- Zuletzt bearbeitet 08.10.2026 15:33:19
- Erkennungen
In apu, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249004; Issue ID: MSV-9170.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mediatek ≫ Mt6899 Firmware Version -
Mediatek ≫ Mt6993 Firmware Version -
Mediatek ≫ Mt8668 Firmware Version -
Mediatek ≫ Mt8781 Firmware Version -
Mediatek ≫ Mt8793 Firmware Version -
Mediatek ≫ Mt8910 Firmware Version -
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.13% | 0.024 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 8.4 | 2.5 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-1285 Improper Validation of Specified Index, Position, or Offset in Input
The product receives input that is expected to specify an index, position, or offset into an indexable resource such as a buffer or file, but it does not validate or incorrectly validates that the specified index/position/offset has the required properties.
https://www.mediatek.com/product-security-bulletin/October-2026