CVE-2023-20690: Integer Overflow
Published Jul 4, 2023
·Updated
In wlan firmware, there is possible system crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664735; Issue ID: ALPS07664735.
Affected Software
12 affected components
linuxfoundation Yocto=4.0
Google Android=11.0
Google Android=12.0
MediaTek Mt6739
MediaTek Mt8167
MediaTek Mt8168
MediaTek Mt8321
MediaTek Mt8365
MediaTek Mt8385
MediaTek Mt8666
MediaTek Mt8765
MediaTek Mt8788
Event History
Jul 4, 2023
CVE Published
via MITRE·01:44 AM
Data Sourced
via MITRE·01:44 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this wlan firmware vulnerability?
The vulnerability ID for this wlan firmware vulnerability is CVE-2023-20690.
2
What is the severity of CVE-2023-20690?
The severity of CVE-2023-20690 is high, with a severity value of 7.5.
3
How can this wlan firmware vulnerability be exploited?
This vulnerability can be exploited to cause a system crash, leading to remote denial of service without the need for user interaction.
4
Which software versions are affected by CVE-2023-20690?
The affected software versions include Linuxfoundation Yocto 4.0, Google Android 11.0, and Google Android 12.0.
5
Is there a patch available for CVE-2023-20690?
Yes, a patch with ID ALPS07664735 is available for CVE-2023-20690.