Vulnerability

CVE-2022-20054

Component: CELLULAR
In ims service, there is a possible AT command injection due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06219083; Issue ID: ALPS06219083.

Impact

Severity (Manufact.)

MEDIUM

Severity (NIST)

7.8

Severity (Android)

N/A

Chipsets

31

Devices

1036

Affected Hardware

NameAlso known asManufacturer
MT6580
MediaTek
MT6739
MediaTek
MT6750
MediaTek
MT6750N
MediaTek
MT6750T
MediaTek
MT6750S
MediaTek
MT6761V/WE
Helio A20
MediaTek
MT6761V/WAB
Helio A22
MediaTek
MT6761V/WBB
Helio A22
MediaTek
MT6762V/WB
Helio A25
MediaTek
31 of 31 row(s) shown.

Rows per page

Page 1 of 4

Timeline

Introduced (est):
Jan 1, 2015
Reported:
Unknown
Advisory Published:
Mar 7, 2022
CVE Published:
Mar 10, 2022
Android Patch Level:
None
For more information and a detailed analysis of the data presented on this website, please see our paper, to be presented at NDSS'25.
Follow us on Twitter