CVE-2023-20694: Medium severity android vulnerability
In preloader, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07733998 / ALPS07874388 (For MT6880 and MT6890 only); Issue ID: ALPS07733998 / ALPS07874388 (For MT6880 and MT6890 only).
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-20694.
What is the severity of vulnerability CVE-2023-20694?
The severity of vulnerability CVE-2023-20694 is high with a severity score of 6.7.
What is affected by vulnerability CVE-2023-20694?
Vulnerability CVE-2023-20694 affects Google Android versions 12.0 and 13.0, as well as Openwrt versions 19.07.0 and 21.02.0.
Is user interaction needed for exploitation of vulnerability CVE-2023-20694?
No, user interaction is not needed for exploitation of vulnerability CVE-2023-20694.
How can I fix vulnerability CVE-2023-20694?
To fix vulnerability CVE-2023-20694, apply the respective patches: ALPS07733998 / ALPS07874388 for MT6880 and MT6890 devices.