Use of Insufficiently Random Values in MediaTek products - CVE-2023-32831
Published: January 2, 2024
Vulnerability identifier: #VU84927
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-32831
CWE-ID: CWE-330
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to use of insufficiently random values within wlan driver. A local application can gain access to sensitive information.
Affected software
MT6890
MT7612
MT7613
MT7615
MT7622
MT7626
MT7629
MT7915
MT7916
MT7981
MT7986
MT7612
MT7613
MT7615
MT7622
MT7626
MT7629
MT7915
MT7916
MT7981
MT7986
How to mitigate CVE-2023-32831
Install security update from vendor's website.