VDB

CVE-2022-20054

CVE-2022-20054 PUBLISHED CVSS 7.800000190734863 HIGH

In ims service, there is a possible AT command injection due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06219083; Issue ID: ALPS06219083.

EPSS 0.22% · 12.4th percentile

Risk Scores

CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.22%
12.4th percentile

Affected Products

VendorProductVersions
googleandroid9.0, 10.0, 12.0
MediaTek, Inc.MT6580, MT6739, MT6750, MT6761, MT6762, MT6763, MT6765, MT6768, MT6771, MT6779, MT8167, MT8168, MT8173, MT8183, MT8185, MT8321, MT8362A, MT8365, MT8385, MT8666, MT8667, MT8675, MT8765, MT8766, MT8768, MT8786, MT8788, MT8789, MT8791, MT8797Android 9.0, 10.0, 11.0, 12.0

Timeline

  • Mar 9, 2022 CVE Published
  • Mar 10, 2022 EPSS Score
  • Mar 18, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Jun 21, 2022 EPSS Score
  • Aug 13, 2022 EPSS Score
  • Oct 3, 2022 EPSS Score
  • Nov 24, 2022 EPSS Score
  • Jan 15, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 28, 2023 EPSS Score
  • Jun 19, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›