Vulnerability
CVE-2022-20059
Component: BOOT
Location: FIRMWARE
In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06160781.
Impact
Severity (Manufact.)
MEDIUM
Severity (NIST)
6.6
Severity (Android)
N/A
Chipsets
52
Devices
1141
Affected Hardware
Name | Also known as | Manufacturer |
---|---|---|
MT6761V/WE | Helio A20 | MediaTek |
MT6761V/WAB | Helio A22 | MediaTek |
MT6761V/WBB | Helio A22 | MediaTek |
MT6762V/WB | Helio A25 | MediaTek |
MT6762V/WD | Helio A25 | MediaTek |
MT6762 | Helio P22 | MediaTek |
MT6765 | Helio P35 | MediaTek |
MT6771 | Helio P60 | MediaTek |
MT6768 | Helio P65 | MediaTek |
MT6771V/CT | Helio P70 | MediaTek |
52 of 52 row(s) shown.
Rows per page
Page 1 of 6
Information reliability
The information on this website is intended to provide information on the big picture of chipset security and measure trends within the industry. Our information is obtained from several vantage points, checked for consistency, and automatically cross-referenced. However, this process may not always yield reliable information. Do not use the information on a particular vulnerability, chipset or device to verify your individual exposure in cases where inaccuracies are inacceptable, for instance to assess risks if you are a Politically Exposed Person.
Timeline
Introduced (est):
Jan 1, 2018
Reported:
Unknown
Advisory Published:
Mar 7, 2022
CVE Published:
Mar 10, 2022
Android Patch Level:
None