CVE-2023-20690

In wlan firmware, there is possible system crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664735; Issue ID: ALPS07664735.
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
OR cpe:2.3:h:mediatek:mt6739:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8167:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8168:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8321:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8365:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8385:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8666:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8765:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8788:-:*:*:*:*:*:*:*

History

07 Jul 2023, 23:57

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8321:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8385:-:*:*:*:*:*:*:*
cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8666:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8365:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8788:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8765:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8168:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6739:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8167:-:*:*:*:*:*:*:*
CWE CWE-190
First Time Mediatek mt8167
Mediatek
Mediatek mt6739
Linuxfoundation
Mediatek mt8666
Linuxfoundation yocto
Mediatek mt8765
Mediatek mt8788
Mediatek mt8168
Mediatek mt8365
Google android
Google
Mediatek mt8385
Mediatek mt8321
References (MISC) https://corp.mediatek.com/product-security-bulletin/July-2023 - (MISC) https://corp.mediatek.com/product-security-bulletin/July-2023 - Vendor Advisory

04 Jul 2023, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-04 02:15

Updated : 2023-07-07 23:57


NVD link : CVE-2023-20690

Mitre link : CVE-2023-20690


JSON object : View

Products Affected

mediatek

  • mt8167
  • mt8365
  • mt8788
  • mt8168
  • mt6739
  • mt8666
  • mt8765
  • mt8321
  • mt8385

linuxfoundation

  • yocto

google

  • android
CWE
CWE-190

Integer Overflow or Wraparound