NULL pointer dereference in MediaTek products - CVE-2022-32663

 

NULL pointer dereference in MediaTek products - CVE-2022-32663

Published: February 7, 2023


Vulnerability identifier: #VU71988
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-32663
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error in Wi-Fi driver. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack.


Affected software

MT7921
MT8788
MT8532
MT8385
MT8365
MT8362A
MT8175
MT8167S
MT7986
MT7981
MT5221
MT7916
MT7915
MT7902
MT7668
MT7629
MT7628
MT7622
MT7615
MT7613
MT7603
MT8518S

How to mitigate CVE-2022-32663

Install updates from vendor's website.


External References

Related Security Bulletins