CVE-2023-20725: Medium severity rdk central rdkb vulnerability
In preloader, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07734004 / ALPS07874358 (For MT6880, MT6890, MT6980, MT6990 only); Issue ID: ALPS07734004 / ALPS07874358 (For MT6880, MT6890, MT6980, MT6990 only).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-20725?
The severity of CVE-2023-20725 is medium with a severity value of 6.7.
How can CVE-2023-20725 be exploited?
CVE-2023-20725 can be exploited without user interaction, leading to local escalation of privilege with system execution privileges.
Which software versions are affected by CVE-2023-20725?
CVE-2023-20725 affects Rdkcentral Rdk-b version 2022q3, Google Android 12.0, Google Android 13.0, Openwrt Openwrt version 19.07.0, and Openwrt Openwrt version 21.02.0.
Is Mediatek Mt6880 affected by CVE-2023-20725?
No, Mediatek Mt6880 is not affected by CVE-2023-20725.
How can CVE-2023-20725 be fixed?
To fix CVE-2023-20725, apply the patch ID ALPS07734004 / ALPS07874358 for the affected software versions.