CVE-2023-20808: Medium severity android vulnerability
Published Aug 7, 2023
·Updated
In OPTEE, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03645895; Issue ID: DTV03645895.
Affected Software
6 affected components
Google Android=11.0
MediaTek Mt9011
MediaTek Mt9022
MediaTek Mt9618
MediaTek Mt9649
MediaTek Mt9653
Event History
Aug 7, 2023
CVE Published
via MITRE·03:21 AM
Data Sourced
via MITRE·03:21 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-20808?
The severity of CVE-2023-20808 is medium with a CVSS score of 6.7.
2
How can CVE-2023-20808 be exploited?
CVE-2023-20808 can be exploited without user interaction, leading to local escalation of privilege.
3
Which software versions are affected by CVE-2023-20808?
Google Android version 11.0 is affected by CVE-2023-20808.
4
Is Mediatek Mt9011 vulnerable to CVE-2023-20808?
No, Mediatek Mt9011 is not vulnerable to CVE-2023-20808.
5
Where can I find more information about CVE-2023-20808?
You can find more information about CVE-2023-20808 [here](https://corp.mediatek.com/product-security-bulletin/August-2023).