CVE-2022-20066
4.4
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Exploitability: 0.8 / Impact: 3.6
Source: NVD
Description
In atf (hwfde), there is a possible leak of sensitive information due to incorrect error handling. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06171729; Issue ID: ALPS06171729.
Affected (2)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.0 |
| Running on/with | Platform Versions |
|---|---|
Mediatek Mt6580 | All versions |
Mediatek Mt6739 | All versions |
Mediatek Mt6761 | All versions |
Mediatek Mt6765 | All versions |
Mediatek Mt6769 | All versions |
Mediatek Mt6771 | All versions |
Mediatek Mt6785 | All versions |
Mediatek Mt6833 | All versions |
Mediatek Mt6873 | All versions |
Mediatek Mt6875 | All versions |
Mediatek Mt6877 | All versions |
Mediatek Mt6891 | All versions |
Mediatek Mt8168 | All versions |
Mediatek Mt8365 | All versions |
Mediatek Mt8666 | All versions |
Mediatek Mt8667 | All versions |
Mediatek Mt8696 | All versions |
Mediatek Mt8766 | All versions |
Mediatek Mt8768 | All versions |
Mediatek Mt8788 | All versions |
References (2)
Source: security@mediatek.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.