Improper input validation in MediaTek products - CVE-2023-20830

 

Improper input validation in MediaTek products - CVE-2023-20830

Published: September 4, 2023


Vulnerability identifier: #VU80283
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20830
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to a missing bounds check within gps. A local privileged application can execute arbitrary code.


Affected software

MT6990
MT6886
MT6890
MT6895
MT6980
MT6983
MT6985
MT8167
MT8167S
MT8168
MT8173
MT8195
MT8362A
MT8365
MT8781
MT2735
MT6761
MT6762
MT6765
MT6768
MT6769
MT6833
MT6835
MT2713
MT6855
MT6879
MT6880
MT6889
MT6891
MT6893
MT6885
MT6853
MT6779
MT6853T
MT6873
MT6875
MT6877
MT6883

How to mitigate CVE-2023-20830

Install security update from vendor's website.


External References

Related Security Bulletins