Vulnerability

CVE-2022-20058

Component: BOOT
Location: FIRMWARE
In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06160485.

Impact

Severity (Manufact.)

MEDIUM

Severity (NIST)

6.6

Severity (Android)

N/A

Chipsets

49

Devices

1127

Affected Hardware

NameAlso known asManufacturer
MT6761V/WE
Helio A20
MediaTek
MT6761V/WAB
Helio A22
MediaTek
MT6761V/WBB
Helio A22
MediaTek
MT6762V/WB
Helio A25
MediaTek
MT6762V/WD
Helio A25
MediaTek
MT6762
Helio P22
MediaTek
MT6765
Helio P35
MediaTek
MT6771
Helio P60
MediaTek
MT6768
Helio P65
MediaTek
MT6771V/CT
Helio P70
MediaTek
49 of 49 row(s) shown.

Rows per page

Page 1 of 5

Timeline

Introduced (est):
Jan 1, 2018
Reported:
Unknown
Advisory Published:
Mar 7, 2022
CVE Published:
Mar 10, 2022
Android Patch Level:
None
For more information and a detailed analysis of the data presented on this website, please see our paper, to be presented at NDSS'25.
Follow us on Twitter