VDB

CVE-2023-20821

CVE-2023-20821 PUBLISHED CVSS 6.699999809265137 MEDIUM

In nvram, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07937113; Issue ID: ALPS07937113.

EPSS 0.09% · 0.6th percentile

Risk Scores

CVSS 3.1
6.699999809265137
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.09%
0.6th percentile

Affected Products

VendorProductVersions
mediatekmt68850
mediatekmt87880
mediatekmt87660
mediatekmt83210
mediatekmt81850
mediatekmt68350
openwrtopenwrt19.07.0, 21.02.0
mediatekmt68950
mediatekmt87860
mediatekmt81730
mediatekmt68750
mediatekmt69800
googleandroid13.0, 12.0
mediatekmt68730
mediatekmt81950
mediatekmt68530
googleandroid11.0, 13.0, 12.0
mediatekmt86750
mediatekmt68830
mediatekmt87810

…and 35 more

Timeline

  • Sep 4, 2023 EPSS Score
  • Sep 4, 2023 CVE Published
  • Oct 7, 2023 EPSS Score
  • Nov 9, 2023 EPSS Score
  • Dec 11, 2023 EPSS Score
  • Jan 13, 2024 EPSS Score
  • Feb 15, 2024 EPSS Score
  • Mar 19, 2024 EPSS Score
  • Apr 21, 2024 EPSS Score
  • May 23, 2024 EPSS Score
  • Jun 25, 2024 EPSS Score
  • Jul 28, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›