Improper input validation in MediaTek products - CVE-2023-20810
Published: August 7, 2023
Vulnerability identifier: #VU79103
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20810
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local privileged application to gain access to sensitive information.
The vulnerability exists due to improper input validation within IOMMU. A local privileged application can gain access to sensitive information.
Affected software
MT9639
MT9611
MT9612
MT9613
MT9615
MT9617
MT9618
MT9629
MT9630
MT9631
MT9632
MT9636
MT9638
MT9610
MT9649
MT9650
MT9652
MT9653
MT9666
MT9667
MT9669
MT9671
MT9675
MT9685
MT9686
MT9688
MT9032
MT5583
MT5691
MT5695
MT9010
MT9011
MT9012
MT9016
MT9020
MT9021
MT9022
MT9030
MT9031
MT5221
MT9216
MT9218
MT9220
MT9221
MT9222
MT9255
MT9256
MT9266
MT9269
MT9286
MT9288
MT9602
MT9611
MT9612
MT9613
MT9615
MT9617
MT9618
MT9629
MT9630
MT9631
MT9632
MT9636
MT9638
MT9610
MT9649
MT9650
MT9652
MT9653
MT9666
MT9667
MT9669
MT9671
MT9675
MT9685
MT9686
MT9688
MT9032
MT5583
MT5691
MT5695
MT9010
MT9011
MT9012
MT9016
MT9020
MT9021
MT9022
MT9030
MT9031
MT5221
MT9216
MT9218
MT9220
MT9221
MT9222
MT9255
MT9256
MT9266
MT9269
MT9286
MT9288
MT9602
How to mitigate CVE-2023-20810
Install security update from vendor's website.