Security Bulletin
This security bulletin contains information about 19 vulnerabilities.
EUVDB-ID: #VU72921
Risk: Low
CVSSv3.1: 2.9 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2021-0415
CWE-ID:
CWE-200 - Information exposure
Exploit availability: No
DescriptionThe vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a missing permission check within memory management driver. A local application can gain access to sensitive information.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6580: All versions
MT6582E: All versions
MT6582H: All versions
MT6582T: All versions
MT6582W: All versions
MT6582_90: All versions
MT6589: All versions
MT6589TD: All versions
MT6592E: All versions
MT6592H: All versions
MT6592T: All versions
MT6592W: All versions
MT6592_90: All versions
MT6595: All versions
MT6731: All versions
MT6732: All versions
MT6735: All versions
MT6737: All versions
MT6739: All versions
MT6750: All versions
MT6750S: All versions
MT6752: All versions
MT6753: All versions
MT6755: All versions
MT6755S: All versions
MT6757: All versions
MT6757C: All versions
MT6757CD: All versions
MT6757CH: All versions
MT6758: All versions
MT6761: All versions
MT6762: All versions
MT6763: All versions
MT6765: All versions
MT6768: All versions
MT6769: All versions
MT6771: All versions
MT6779: All versions
MT6785: All versions
MT6795: All versions
MT6797: All versions
MT6799: All versions
MT6833: All versions
MT6853: All versions
MT6853T: All versions
MT6873: All versions
MT6875: All versions
MT6877: All versions
MT6883: All versions
MT6885: All versions
MT6889: All versions
MT6891: All versions
MT6893: All versions
External linkshttp://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72929
Risk: Low
CVSSv3.1: 5.8 [CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2021-0628
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to improper input validation within OMA DRM. A local privileged application can execute arbitrary code.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6580: All versions
MT6735: All versions
MT6739: All versions
MT6755S: All versions
MT6757: All versions
MT6761: All versions
MT6763: All versions
MT6765: All versions
MT6768: All versions
MT6771: All versions
MT6779: All versions
MT6785: All versions
MT6833: All versions
MT6853: All versions
MT6873: All versions
MT6877: All versions
MT6885: All versions
External linkshttp://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72928
Risk: Low
CVSSv3.1: 5.8 [CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2021-0627
CWE-ID:
CWE-190 - Integer overflow
Exploit availability: No
DescriptionThe vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to an integer overflow within OMA DRM. A local privileged application can execute arbitrary code.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6580: All versions
MT6735: All versions
MT6739: All versions
MT6755S: All versions
MT6757: All versions
MT6761: All versions
MT6763: All versions
MT6765: All versions
MT6768: All versions
MT6771: All versions
MT6785: All versions
MT6833: All versions
MT6853: All versions
MT6873: All versions
MT6877: All versions
MT6885: All versions
External linkshttp://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72927
Risk: Low
CVSSv3.1: 5.8 [CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2021-0626
CWE-ID:
CWE-787 - Out-of-bounds write
Exploit availability: No
DescriptionThe vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to a missing bounds check within ged. A local privileged application can execute arbitrary code.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6768: All versions
MT6771: All versions
MT6779: All versions
MT6785: All versions
External linkshttp://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72926
Risk: Low
CVSSv3.1: 2.9 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]
CVE-ID: CVE-2021-0420
CWE-ID:
CWE-400 - Resource exhaustion
Exploit availability: No
DescriptionThe vulnerability allows a local application to perform service disruption.
The vulnerability exists due to a missing bounds check within memory management driver. A local application can perform service disruption.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6580: All versions
MT6582E: All versions
MT6582H: All versions
MT6582T: All versions
MT6582W: All versions
MT6582_90: All versions
MT6589: All versions
MT6589TD: All versions
MT6592E: All versions
MT6592H: All versions
MT6592T: All versions
MT6592W: All versions
MT6592_90: All versions
MT6595: All versions
MT6731: All versions
MT6732: All versions
MT6735: All versions
MT6737: All versions
MT6739: All versions
MT6750: All versions
MT6750S: All versions
MT6752: All versions
MT6753: All versions
MT6755: All versions
MT6755S: All versions
MT6757: All versions
MT6757C: All versions
MT6757CD: All versions
MT6757CH: All versions
MT6758: All versions
MT6761: All versions
MT6762: All versions
MT6763: All versions
MT6765: All versions
MT6768: All versions
MT6769: All versions
MT6771: All versions
MT6779: All versions
MT6785: All versions
MT6795: All versions
MT6797: All versions
MT6799: All versions
MT6833: All versions
MT6853: All versions
MT6853T: All versions
MT6873: All versions
MT6875: All versions
MT6877: All versions
MT6883: All versions
MT6885: All versions
MT6889: All versions
MT6891: All versions
MT6893: All versions
External linkshttp://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72925
Risk: Low
CVSSv3.1: 2.9 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]
CVE-ID: CVE-2021-0419
CWE-ID:
CWE-400 - Resource exhaustion
Exploit availability: No
DescriptionThe vulnerability allows a local application to perform service disruption.
The vulnerability exists due to improper input validation within memory management driver. A local application can perform service disruption.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6580: All versions
MT6582E: All versions
MT6582H: All versions
MT6582T: All versions
MT6582W: All versions
MT6582_90: All versions
MT6589: All versions
MT6589TD: All versions
MT6592E: All versions
MT6592H: All versions
MT6592T: All versions
MT6592W: All versions
MT6592_90: All versions
MT6595: All versions
MT6731: All versions
MT6732: All versions
MT6735: All versions
MT6737: All versions
MT6739: All versions
MT6750: All versions
MT6750S: All versions
MT6752: All versions
MT6753: All versions
MT6755: All versions
MT6755S: All versions
MT6757: All versions
MT6757C: All versions
MT6757CD: All versions
MT6757CH: All versions
MT6758: All versions
MT6761: All versions
MT6762: All versions
MT6763: All versions
MT6765: All versions
MT6768: All versions
MT6769: All versions
MT6771: All versions
MT6779: All versions
MT6785: All versions
MT6795: All versions
MT6797: All versions
MT6799: All versions
MT6833: All versions
MT6853: All versions
MT6853T: All versions
MT6873: All versions
MT6875: All versions
MT6877: All versions
MT6883: All versions
MT6885: All versions
MT6889: All versions
MT6891: All versions
MT6893: All versions
External linkshttp://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72924
Risk: Low
CVSSv3.1: 2.9 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]
CVE-ID: CVE-2021-0418
CWE-ID:
CWE-400 - Resource exhaustion
Exploit availability: No
DescriptionThe vulnerability allows a local application to perform service disruption.
The vulnerability exists due to improper input validation within memory management driver. A local application can perform service disruption.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6580: All versions
MT6582E: All versions
MT6582H: All versions
MT6582T: All versions
MT6582W: All versions
MT6582_90: All versions
MT6589: All versions
MT6589TD: All versions
MT6592E: All versions
MT6592H: All versions
MT6592T: All versions
MT6592W: All versions
MT6592_90: All versions
MT6595: All versions
MT6731: All versions
MT6732: All versions
MT6735: All versions
MT6737: All versions
MT6739: All versions
MT6750: All versions
MT6750S: All versions
MT6752: All versions
MT6753: All versions
MT6755: All versions
MT6755S: All versions
MT6757: All versions
MT6757C: All versions
MT6757CD: All versions
MT6757CH: All versions
MT6758: All versions
MT6761: All versions
MT6762: All versions
MT6763: All versions
MT6765: All versions
MT6768: All versions
MT6769: All versions
MT6771: All versions
MT6779: All versions
MT6785: All versions
MT6795: All versions
MT6797: All versions
MT6799: All versions
MT6833: All versions
MT6853: All versions
MT6853T: All versions
MT6873: All versions
MT6875: All versions
MT6877: All versions
MT6883: All versions
MT6885: All versions
MT6889: All versions
MT6891: All versions
MT6893: All versions
External linkshttp://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72923
Risk: Low
CVSSv3.1: 2.9 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2021-0417
CWE-ID:
CWE-330 - Use of Insufficiently Random Values
Exploit availability: No
DescriptionThe vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improper input validation within memory management driver. A local application can gain access to sensitive information.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6580: All versions
MT6582E: All versions
MT6582H: All versions
MT6582T: All versions
MT6582W: All versions
MT6582_90: All versions
MT6589: All versions
MT6589TD: All versions
MT6592E: All versions
MT6592H: All versions
MT6592T: All versions
MT6592W: All versions
MT6592_90: All versions
MT6595: All versions
MT6731: All versions
MT6732: All versions
MT6735: All versions
MT6737: All versions
MT6739: All versions
MT6750: All versions
MT6750S: All versions
MT6752: All versions
MT6753: All versions
MT6755: All versions
MT6755S: All versions
MT6757: All versions
MT6757C: All versions
MT6757CD: All versions
MT6757CH: All versions
MT6758: All versions
MT6761: All versions
MT6762: All versions
MT6763: All versions
MT6765: All versions
MT6768: All versions
MT6769: All versions
MT6771: All versions
MT6779: All versions
MT6785: All versions
MT6795: All versions
MT6797: All versions
MT6799: All versions
MT6833: All versions
MT6853: All versions
MT6853T: All versions
MT6873: All versions
MT6875: All versions
MT6877: All versions
MT6883: All versions
MT6885: All versions
MT6889: All versions
MT6891: All versions
MT6893: All versions
External linkshttp://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72922
Risk: Low
CVSSv3.1: 2.9 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2021-0416
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improper input validation within memory management driver. A local application can gain access to sensitive information.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6580: All versions
MT6582E: All versions
MT6582H: All versions
MT6582T: All versions
MT6582W: All versions
MT6582_90: All versions
MT6589: All versions
MT6589TD: All versions
MT6592E: All versions
MT6592H: All versions
MT6592T: All versions
MT6592W: All versions
MT6592_90: All versions
MT6595: All versions
MT6731: All versions
MT6732: All versions
MT6735: All versions
MT6737: All versions
MT6739: All versions
MT6750: All versions
MT6750S: All versions
MT6752: All versions
MT6753: All versions
MT6755: All versions
MT6755S: All versions
MT6757: All versions
MT6757C: All versions
MT6757CD: All versions
MT6757CH: All versions
MT6758: All versions
MT6761: All versions
MT6762: All versions
MT6763: All versions
MT6765: All versions
MT6768: All versions
MT6769: All versions
MT6771: All versions
MT6779: All versions
MT6785: All versions
MT6795: All versions
MT6797: All versions
MT6799: All versions
MT6833: All versions
MT6853: All versions
MT6853T: All versions
MT6873: All versions
MT6875: All versions
MT6877: All versions
MT6883: All versions
MT6885: All versions
MT6889: All versions
MT6891: All versions
MT6893: All versions
External linkshttp://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72920
Risk: Low
CVSSv3.1: 2.9 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2021-0408
CWE-ID:
CWE-703 - Improper Check or Handling of Exceptional Conditions
Exploit availability: No
DescriptionThe vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to an incorrect bounds check within asf extractor. A local application can gain access to sensitive information.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6570: All versions
MT6580: All versions
MT6735: All versions
MT6737: All versions
MT6739: All versions
MT6750: All versions
MT6750S: All versions
MT6753: All versions
MT6755: All versions
MT6755S: All versions
MT6757: All versions
MT6757C: All versions
MT6757CD: All versions
MT6757CH: All versions
MT6758: All versions
MT6761: All versions
MT6762: All versions
MT6763: All versions
MT6765: All versions
MT6768: All versions
MT6771: All versions
MT6779: All versions
MT6785: All versions
MT6797: All versions
MT6799: All versions
MT6833: All versions
MT6853: All versions
MT6853T: All versions
MT6873: All versions
MT6877: All versions
MT6885: All versions
MT6889: All versions
MT6893: All versions
External linkshttp://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72911
Risk: Low
CVSSv3.1: 6.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2021-0573
CWE-ID:
CWE-703 - Improper Check or Handling of Exceptional Conditions
Exploit availability: No
DescriptionThe vulnerability allows a local application to execute arbitrary code.
The vulnerability exists due to a missing bounds check within asf extractor. A local application can execute arbitrary code.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6570: All versions
MT6580: All versions
MT6735: All versions
MT6737: All versions
MT6739: All versions
MT6750: All versions
MT6750S: All versions
MT6753: All versions
MT6755: All versions
MT6755S: All versions
MT6757: All versions
MT6757C: All versions
MT6757CD: All versions
MT6757CH: All versions
MT6758: All versions
MT6761: All versions
MT6762: All versions
MT6763: All versions
MT6765: All versions
MT6768: All versions
MT6771: All versions
MT6779: All versions
MT6785: All versions
MT6797: All versions
MT6799: All versions
MT6833: All versions
MT6853: All versions
MT6853T: All versions
MT6873: All versions
MT6877: All versions
MT6885: All versions
MT6889: All versions
MT6893: All versions
External linkshttp://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72919
Risk: Low
CVSSv3.1: 5.8 [CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2021-0407
CWE-ID:
CWE-123 - Write-what-where Condition
Exploit availability: No
DescriptionThe vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to an incorrect bounds check within clk driver. A local privileged application can execute arbitrary code.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6739: All versions
MT6761: All versions
MT6762: All versions
MT6763: All versions
MT6765: All versions
MT6768: All versions
MT6769: All versions
MT6771: All versions
MT6833: All versions
MT6853: All versions
MT6853T: All versions
MT6873: All versions
MT6885: All versions
MT6889: All versions
MT6893: All versions
External linkshttp://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72918
Risk: Low
CVSSv3.1: 2.9 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2021-0582
CWE-ID:
CWE-125 - Out-of-bounds read
Exploit availability: No
DescriptionThe vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a missing bounds check within wifi driver. A local application can gain access to sensitive information.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6761: All versions
MT6762: All versions
MT6765: All versions
MT6768: All versions
MT6779: All versions
MT6785: All versions
MT6833: All versions
MT6853: All versions
MT6873: All versions
MT6875: All versions
MT6877: All versions
MT6883: All versions
MT6885: All versions
MT6889: All versions
MT6891: All versions
MT6893: All versions
External linkshttp://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72917
Risk: Low
CVSSv3.1: 2.9 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2021-0581
CWE-ID:
CWE-125 - Out-of-bounds read
Exploit availability: No
DescriptionThe vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a missing bounds check within wifi driver. A local application can gain access to sensitive information.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6761: All versions
MT6762: All versions
MT6765: All versions
MT6768: All versions
MT6779: All versions
MT6785: All versions
MT6833: All versions
MT6853: All versions
MT6873: All versions
MT6875: All versions
MT6877: All versions
MT6883: All versions
MT6885: All versions
MT6889: All versions
MT6891: All versions
MT6893: All versions
External linkshttp://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72916
Risk: Low
CVSSv3.1: 2.9 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2021-0580
CWE-ID:
CWE-191 - Integer underflow
Exploit availability: No
DescriptionThe vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a missing bounds check within wifi driver. A local application can gain access to sensitive information.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6761: All versions
MT6762: All versions
MT6765: All versions
MT6768: All versions
MT6779: All versions
MT6785: All versions
MT6833: All versions
MT6853: All versions
MT6873: All versions
MT6875: All versions
MT6877: All versions
MT6883: All versions
MT6885: All versions
MT6889: All versions
MT6891: All versions
MT6893: All versions
External linkshttp://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72915
Risk: Low
CVSSv3.1: 2.9 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2021-0579
CWE-ID:
CWE-126 - Buffer over-read
Exploit availability: No
DescriptionThe vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a missing bounds check within wifi driver. A local application can gain access to sensitive information.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6761: All versions
MT6762: All versions
MT6765: All versions
MT6768: All versions
MT6779: All versions
MT6785: All versions
MT6833: All versions
MT6853: All versions
MT6873: All versions
MT6875: All versions
MT6877: All versions
MT6883: All versions
MT6885: All versions
MT6889: All versions
MT6891: All versions
MT6893: All versions
External linkshttp://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72914
Risk: Low
CVSSv3.1: 2.9 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2021-0578
CWE-ID:
CWE-125 - Out-of-bounds read
Exploit availability: No
DescriptionThe vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a missing bounds check within wifi driver. A local application can gain access to sensitive information.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6761: All versions
MT6762: All versions
MT6765: All versions
MT6768: All versions
MT6779: All versions
MT6785: All versions
MT6833: All versions
MT6853: All versions
MT6873: All versions
MT6875: All versions
MT6877: All versions
MT6883: All versions
MT6885: All versions
MT6889: All versions
MT6891: All versions
MT6893: All versions
External linkshttp://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72913
Risk: Low
CVSSv3.1: 6.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2021-0576
CWE-ID:
CWE-122 - Heap-based Buffer Overflow
Exploit availability: No
DescriptionThe vulnerability allows a local application to execute arbitrary code.
The vulnerability exists due to a missing bounds check within flv extractor. A local application can execute arbitrary code.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6570: All versions
MT6580: All versions
MT6735: All versions
MT6737: All versions
MT6739: All versions
MT6750: All versions
MT6750S: All versions
MT6753: All versions
MT6755: All versions
MT6755S: All versions
MT6757: All versions
MT6757C: All versions
MT6757CD: All versions
MT6757CH: All versions
MT6758: All versions
MT6761: All versions
MT6762: All versions
MT6763: All versions
MT6765: All versions
MT6768: All versions
MT6771: All versions
MT6779: All versions
MT6785: All versions
MT6797: All versions
MT6799: All versions
MT6833: All versions
MT6853: All versions
MT6853T: All versions
MT6873: All versions
MT6877: All versions
MT6885: All versions
MT6889: All versions
MT6893: All versions
External linkshttp://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72912
Risk: Low
CVSSv3.1: 6.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2021-0574
CWE-ID:
CWE-787 - Out-of-bounds write
Exploit availability: No
DescriptionThe vulnerability allows a local application to execute arbitrary code.
The vulnerability exists due to a missing bounds check within asf extractor. A local application can execute arbitrary code.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6570: All versions
MT6580: All versions
MT6735: All versions
MT6737: All versions
MT6739: All versions
MT6750: All versions
MT6750S: All versions
MT6753: All versions
MT6755: All versions
MT6755S: All versions
MT6757: All versions
MT6757C: All versions
MT6757CD: All versions
MT6757CH: All versions
MT6758: All versions
MT6761: All versions
MT6762: All versions
MT6763: All versions
MT6765: All versions
MT6768: All versions
MT6771: All versions
MT6779: All versions
MT6785: All versions
MT6797: All versions
MT6799: All versions
MT6833: All versions
MT6853: All versions
MT6853T: All versions
MT6873: All versions
MT6877: All versions
MT6885: All versions
MT6889: All versions
MT6893: All versions
External linkshttp://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.