CVE-2023-32811: Input Validation
Published Sep 4, 2023
·Updated
In connectivity system driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07929848; Issue ID: ALPS07929848.
Affected Software
44 affected components
All of the following
Any of the following
linuxfoundation Yocto=4.0
MediaTek Iot Yocto=23.0
Google Android=12.0
Google Android=13.0
Any of the following
MediaTek Mt2713
MediaTek Mt6779
MediaTek Mt6781
MediaTek Mt6785
MediaTek Mt6789
MediaTek Mt6833
MediaTek Mt6835
MediaTek Mt6853
MediaTek Mt6855
MediaTek Mt6873
MediaTek Mt8168
MediaTek Mt8175
MediaTek Mt8188
MediaTek Mt8195
MediaTek Mt8365
MediaTek Mt8666
MediaTek Mt8667
MediaTek Mt8673
linuxfoundation Yocto=4.0
MediaTek Iot Yocto=23.0
Google Android=12.0
Google Android=13.0
MediaTek Mt2713
MediaTek Mt6779
MediaTek Mt6781
MediaTek Mt6785
MediaTek Mt6789
MediaTek Mt6833
MediaTek Mt6835
MediaTek Mt6853
MediaTek Mt6855
MediaTek Mt6873
MediaTek Mt8168
MediaTek Mt8175
MediaTek Mt8188
MediaTek Mt8195
MediaTek Mt8365
MediaTek Mt8666
MediaTek Mt8667
MediaTek Mt8673
Event History
Sep 4, 2023
CVE Published
via MITRE·02:28 AM
Data Sourced
via MITRE·02:28 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2023-32811.
2
What is the severity level of CVE-2023-32811?
The severity level of CVE-2023-32811 is medium (6.7).
3
How does CVE-2023-32811 affect Linuxfoundation Yocto?
Linuxfoundation Yocto is affected by CVE-2023-32811.
4
Is user interaction required for exploitation of CVE-2023-32811?
No, user interaction is not needed for exploitation of CVE-2023-32811.
5
Where can I find more information about CVE-2023-32811?
More information about CVE-2023-32811 can be found at https://corp.mediatek.com/product-security-bulletin/September-2023.