- Description
- The MediaTek Embedded Multimedia Card (eMMC) subsystem for Android on MT65xx, MT66xx, and MT8163 SoC devices allows attackers to execute arbitrary commands as root via shell metacharacters in a filename under /data, because clear_emmc_nomedia_entry in platform/mt6577/external/meta/emmc/meta_clr_emmc.c invokes 'system("/system/bin/rm -r /data/' followed by this filename upon an eMMC clearance from a Meta Mode boot. NOTE: compromise of Fire OS on the Amazon Echo Dot would require a second hypothetical vulnerability that allows creation of the required file under /data.
- Source
- cve@mitre.org
- NVD status
- Analyzed
CVSS 3.0
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
CVSS 2.0
- Type
- Primary
- Base score
- 10
- Impact score
- 10
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:C/I:C/A:C
- nvd@nist.gov
- CWE-78
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:mediatek:mt8163_firmware:-:*:*:*:*:android:*:*",
"vulnerable": true,
"matchCriteriaId": "EBC8DF79-7DB0-4F5C-8D86-AB2D39C49B31"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:mediatek:mt8163:-:*:*:*:*:android:*:*",
"vulnerable": false,
"matchCriteriaId": "2A270FFF-F61C-4BFF-B208-D0EEE5602E41"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:mediatek:mt6625_firmware:-:*:*:*:*:android:*:*",
"vulnerable": true,
"matchCriteriaId": "A35C889C-6624-4CD2-8449-0B6F1CB18ACA"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:mediatek:mt6625:-:*:*:*:*:android:*:*",
"vulnerable": false,
"matchCriteriaId": "BA6F0E45-C3BA-4933-8617-8461EFC664E0"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:mediatek:mt6577_firmware:-:*:*:*:*:android:*:*",
"vulnerable": true,
"matchCriteriaId": "68D537A1-141F-44EB-BFD6-61526576E2EA"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:mediatek:mt6577:-:*:*:*:*:android:*:*",
"vulnerable": false,
"matchCriteriaId": "BAAF1611-7AD6-48C9-BB93-BDABCD3C1A50"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
]