#VU71988 NULL pointer dereference in MediaTek products - CVE-2022-32663
Published: February 7, 2023
Vulnerability identifier: #VU71988
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2022-32663
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
MT5221
MT7603
MT7613
MT7615
MT7622
MT7628
MT7629
MT7668
MT7902
MT7915
MT7916
MT7921
MT7981
MT7986
MT8167S
MT8175
MT8362A
MT8365
MT8385
MT8532
MT8788
MT8518S
MT5221
MT7603
MT7613
MT7615
MT7622
MT7628
MT7629
MT7668
MT7902
MT7915
MT7916
MT7921
MT7981
MT7986
MT8167S
MT8175
MT8362A
MT8365
MT8385
MT8532
MT8788
MT8518S
Software vendor:
MediaTek
MediaTek
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in Wi-Fi driver. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack.
Remediation
Install updates from vendor's website.