Vulnerability

CVE-2022-20081

Component: POSITION
In A-GPS, there is a possible man in the middle attack due to improper certificate validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06461919; Issue ID: ALPS06461919.

Impact

Severity (Manufact.)

HIGH

Severity (NIST)

5.9

Severity (Android)

N/A

Chipsets

80

Devices

1378

Affected Hardware

NameAlso known asManufacturer
MT6580
MediaTek
MT6735P
MediaTek
MT6735M
MediaTek
MT6735
MediaTek
MT6737
MediaTek
MT6737T
MediaTek
MT6739
MediaTek
MT6753
MediaTek
MT6761V/WE
Helio A20
MediaTek
MT6761V/WAB
Helio A22
MediaTek
80 of 80 row(s) shown.

Rows per page

Page 1 of 8

Timeline

Introduced (est):
Jan 1, 2015
Reported:
Unknown
Advisory Published:
Apr 6, 2022
CVE Published:
Apr 11, 2022
Android Patch Level:
Apr 2022
For more information and a detailed analysis of the data presented on this website, please see our paper, to be presented at NDSS'25.
Follow us on Twitter