CVE-2022-20021
6.5
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: NVD
Description
In Bluetooth, there is a possible application crash due to bluetooth does not properly handle the reception of multiple LMP_host_connection_req. This could lead to remote denial of service of bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06198513; Issue ID: ALPS06198513.
Affected (2)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
| Running on/with | Platform Versions |
|---|---|
Mediatek Awus036nh | All versions |
Mediatek Mt6580 | All versions |
Mediatek Mt6630 | All versions |
Mediatek Mt6735 | All versions |
Mediatek Mt6737 | All versions |
Mediatek Mt6739 | All versions |
Mediatek Mt6750s | All versions |
Mediatek Mt6753 | All versions |
Mediatek Mt6755s | All versions |
Mediatek Mt6757 | All versions |
Mediatek Mt6757c | All versions |
Mediatek Mt6757cd | All versions |
Mediatek Mt6757ch | All versions |
Mediatek Mt6763 | All versions |
Mediatek Mt6771 | All versions |
Mediatek Mt7662t | All versions |
Mediatek Mt7663 | All versions |
Mediatek Mt7668 | All versions |
Mediatek Mt8163 | All versions |
Mediatek Mt8167 | All versions |
Mediatek Mt8167s | All versions |
Mediatek Mt8173 | All versions |
Mediatek Mt8183 | All versions |
Mediatek Mt8321 | All versions |
Mediatek Mt8362a | All versions |
Mediatek Mt8362b | All versions |
Mediatek Mt8385 | All versions |
Mediatek Mt8765 | All versions |
Mediatek Mt8788 | All versions |
References (2)
Source: security@mediatek.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.