← Voltar para CVEs
CVE-2025-20643
LOW3.9
Descricao
In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS09291146; Issue ID: MSV-2056.
Detalhes CVE
Pontuacao CVSS v3.13.9
SeveridadeLOW
Vetor CVSSCVSS:3.1/AV:P/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
Vetor de ataquePHYSICAL
ComplexidadeLOW
Privilegios necessariosHIGH
Interacao do usuarioREQUIRED
Publicado2/3/2025
Ultima modificacao2/4/2025
Fontenvd
Avistamentos honeypot0
Produtos afetados
google:androidmediatek:mt6739mediatek:mt6761mediatek:mt6765mediatek:mt6768mediatek:mt6771mediatek:mt6779mediatek:mt6781mediatek:mt6785mediatek:mt6833mediatek:mt6853mediatek:mt6873mediatek:mt6877mediatek:mt6885mediatek:mt6893mediatek:mt8167mediatek:mt8167smediatek:mt8175mediatek:mt8185mediatek:mt8195mediatek:mt8321mediatek:mt8362amediatek:mt8365mediatek:mt8385mediatek:mt8395mediatek:mt8666mediatek:mt8667mediatek:mt8673mediatek:mt8675mediatek:mt8678mediatek:mt8765mediatek:mt8766mediatek:mt8768mediatek:mt8771mediatek:mt8775mediatek:mt8781mediatek:mt8786mediatek:mt8788mediatek:mt8789mediatek:mt8791tmediatek:mt8795tmediatek:mt8797mediatek:mt8798mediatek:mt8893
Fraquezas (CWE)
CWE-1295CWE-125
Referencias
https://corp.mediatek.com/product-security-bulletin/February-2025(security@mediatek.com)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.