CVE-2023-32820
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
In wlan firmware, there is a possible firmware assertion due to improper input handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07932637; Issue ID: ALPS07932637.
Affected (7)
Show all products
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.0 | |
| Version 4.19 | |
| Version 3.1 | |
| Version 23.0 |
| Running on/with | Platform Versions |
|---|---|
Mediatek Mt5221 | All versions |
Mediatek Mt6781 | All versions |
Mediatek Mt6833 | All versions |
Mediatek Mt6853 | All versions |
Mediatek Mt6853t | All versions |
Mediatek Mt6855 | All versions |
Mediatek Mt6873 | All versions |
Mediatek Mt6875 | All versions |
Mediatek Mt6877 | All versions |
Mediatek Mt6879 | All versions |
Mediatek Mt6883 | All versions |
Mediatek Mt6885 | All versions |
Mediatek Mt6886 | All versions |
Mediatek Mt6889 | All versions |
Mediatek Mt6891 | All versions |
Mediatek Mt6893 | All versions |
Mediatek Mt6895 | All versions |
Mediatek Mt6983 | All versions |
Mediatek Mt6985 | All versions |
Mediatek Mt7663 | All versions |
Mediatek Mt7668 | All versions |
Mediatek Mt7902 | All versions |
Mediatek Mt7921 | All versions |
Mediatek Mt8168 | All versions |
Mediatek Mt8365 | All versions |
Mediatek Mt8518s | All versions |
Mediatek Mt8532 | All versions |
Mediatek Mt8666 | All versions |
Mediatek Mt8673 | All versions |
Mediatek Mt8675 | All versions |
Mediatek Mt8695 | All versions |
Mediatek Mt8766 | All versions |
Mediatek Mt8768 | All versions |
Mediatek Mt8781 | All versions |
Mediatek Mt8786 | All versions |
Mediatek Mt8789 | All versions |
Mediatek Mt8791 | All versions |
Mediatek Mt8797 | All versions |
Mediatek Mt8798 | All versions |
Related CWEs
CWE-20
Improper Input Validation
The product receives input or data, but it does
not validate or incorrectly validates that the input has the
properties that are required to process the data safely and
correctly.
CWE-617
Reachable Assertion
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
References (2)
Source: security@mediatek.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.