TROYANOSYVIRUS
Back to CVEs

CVE-2025-20643

LOW
3.9

Description

In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS09291146; Issue ID: MSV-2056.

CVE Details

CVSS v3.1 Score3.9
SeverityLOW
CVSS VectorCVSS:3.1/AV:P/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
Attack VectorPHYSICAL
ComplexityLOW
Privileges RequiredHIGH
User InteractionREQUIRED
Published2/3/2025
Last Modified2/4/2025
Sourcenvd
Honeypot Sightings0

Affected Products

google:androidmediatek:mt6739mediatek:mt6761mediatek:mt6765mediatek:mt6768mediatek:mt6771mediatek:mt6779mediatek:mt6781mediatek:mt6785mediatek:mt6833mediatek:mt6853mediatek:mt6873mediatek:mt6877mediatek:mt6885mediatek:mt6893mediatek:mt8167mediatek:mt8167smediatek:mt8175mediatek:mt8185mediatek:mt8195mediatek:mt8321mediatek:mt8362amediatek:mt8365mediatek:mt8385mediatek:mt8395mediatek:mt8666mediatek:mt8667mediatek:mt8673mediatek:mt8675mediatek:mt8678mediatek:mt8765mediatek:mt8766mediatek:mt8768mediatek:mt8771mediatek:mt8775mediatek:mt8781mediatek:mt8786mediatek:mt8788mediatek:mt8789mediatek:mt8791tmediatek:mt8795tmediatek:mt8797mediatek:mt8798mediatek:mt8893

Weaknesses (CWE)

CWE-1295CWE-125

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.