CVE-2022-20034
Published Feb 9, 2022
Last updated 3 years ago
Overview
- Description
- In Preloader XFLASH, there is a possible escalation of privilege due to an improper certificate validation. This could lead to local escalation of privilege for an attacker who has physical access to the device with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06160806.
- Source
- security@mediatek.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 6.8
- Impact score
- 5.9
- Exploitability score
- 0.9
- Vector string
- CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 4.6
- Impact score
- 6.4
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-295
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "109DD7FD-3A48-4C3D-8E1A-4433B98E1E64" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:mediatek:mt6580:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "46F71838-4E50-4F2A-9EB8-30AE5DF8511E" }, { "criteria": "cpe:2.3:h:mediatek:mt6735:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "C82E144B-0BAD-47E1-A657-3A5880988FE2" }, { "criteria": "cpe:2.3:h:mediatek:mt6739:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "7FA8A390-9F52-4CF3-9B45-936CE3E2B828" }, { "criteria": "cpe:2.3:h:mediatek:mt6761:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F726F486-A86F-4215-AD93-7A07A071844A" }, { "criteria": "cpe:2.3:h:mediatek:mt6763:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "2F19C76A-50DF-4ACA-BACA-07157B4D838B" }, { "criteria": "cpe:2.3:h:mediatek:mt6765:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "43E779F6-F0A0-4153-9A1D-B715C3A2F80E" }, { "criteria": "cpe:2.3:h:mediatek:mt6768:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "06CD97E1-8A76-48B4-9780-9698EF5A960F" }, { "criteria": "cpe:2.3:h:mediatek:mt6769:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "D23991D5-1893-49F4-8A06-D5E66C96C3B3" }, { "criteria": "cpe:2.3:h:mediatek:mt6771:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "BE4D2AED-C713-407F-A34A-52C3D8F65835" }, { "criteria": "cpe:2.3:h:mediatek:mt6779:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "EBA369B8-8E23-492B-82CC-23114E6A5D1C" }, { "criteria": "cpe:2.3:h:mediatek:mt6781:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "C4EEE021-6B2A-47A0-AC6B-55525A40D718" }, { "criteria": "cpe:2.3:h:mediatek:mt6785:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "A82E0A4F-072F-474C-B94C-8114ABE05639" }, { "criteria": "cpe:2.3:h:mediatek:mt6799:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "FC0CAAE1-2BC9-49CA-AC68-2217A4258BDD" }, { "criteria": "cpe:2.3:h:mediatek:mt6833:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "9814939B-F05E-4870-90C0-7C0F6BAAEB39" }, { "criteria": "cpe:2.3:h:mediatek:mt6853:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "366F1912-756B-443E-9962-224937DD7DFB" }, { "criteria": "cpe:2.3:h:mediatek:mt6873:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F6B8A36E-C5FB-44AE-A1C3-50EBF4C68F6B" }, { "criteria": "cpe:2.3:h:mediatek:mt6875:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "80BDC5EC-E822-4BC7-8C0D-E8AD8396E8FE" }, { "criteria": "cpe:2.3:h:mediatek:mt6877:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "7CA9352F-E9BD-4656-9B7C-4AFEE2C78E58" }, { "criteria": "cpe:2.3:h:mediatek:mt6885:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "DD64413C-C774-4C4F-9551-89E1AA9469EE" }, { "criteria": "cpe:2.3:h:mediatek:mt6891:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "D8E91CA4-CA5B-40D1-9A96-2B875104BCF4" }, { "criteria": "cpe:2.3:h:mediatek:mt6893:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "213B5C7F-D965-4312-9CDF-4F06FA77D401" } ], "operator": "OR" } ], "operator": "AND" } ]