CVE-2022-20066

In atf (hwfde), there is a possible leak of sensitive information due to incorrect error handling. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06171729; Issue ID: ALPS06171729.
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
OR cpe:2.3:h:mediatek:mt6580:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6739:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6761:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6765:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6769:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6771:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6785:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6833:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6873:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6875:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6877:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6891:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8168:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8365:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8666:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8667:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8696:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8766:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8768:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8788:-:*:*:*:*:*:*:*

History

09 Sep 2022, 16:47

Type Values Removed Values Added
References (MISC) https://corp.mediatek.com/product-security-bulletin/May-2022 - (MISC) https://corp.mediatek.com/product-security-bulletin/May-2022 - Vendor Advisory
CPE cpe:2.3:h:mediatek:mt6891:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6580:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6875:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8766:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8768:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6833:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6785:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6877:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6771:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6873:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6761:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6769:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8788:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6739:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6765:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8666:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8667:-:*:*:*:*:*:*:*
First Time Mediatek mt6580
Mediatek mt6771
Mediatek mt8768
Mediatek mt6785
Mediatek mt6765
Mediatek mt8666
Mediatek mt6833
Mediatek mt6761
Mediatek mt6891
Mediatek mt8788
Mediatek mt6875
Mediatek mt6877
Mediatek mt6739
Mediatek mt8667
Mediatek mt6769
Mediatek mt6873
Mediatek mt8766

03 May 2022, 21:15

Type Values Removed Values Added
References
  • {'url': 'https://corp.mediatek.com/product-security-bulletin/April-2022', 'name': 'https://corp.mediatek.com/product-security-bulletin/April-2022', 'tags': ['Vendor Advisory'], 'refsource': 'MISC'}
  • (MISC) https://corp.mediatek.com/product-security-bulletin/May-2022 -

18 Apr 2022, 17:50

Type Values Removed Values Added
First Time Mediatek mt8696
Mediatek mt8365
Google android
Mediatek
Google
Mediatek mt8168
CWE CWE-755
CVSS v2 : unknown
v3 : unknown
v2 : 2.1
v3 : 4.4
References (MISC) https://corp.mediatek.com/product-security-bulletin/April-2022 - (MISC) https://corp.mediatek.com/product-security-bulletin/April-2022 - Vendor Advisory
CPE cpe:2.3:h:mediatek:mt8365:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8168:-:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8696:-:*:*:*:*:*:*:*
cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*

11 Apr 2022, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-04-11 20:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-20066

Mitre link : CVE-2022-20066

CVE.ORG link : CVE-2022-20066


JSON object : View

Products Affected

mediatek

  • mt6875
  • mt8788
  • mt8168
  • mt8768
  • mt8666
  • mt6769
  • mt6873
  • mt6833
  • mt8766
  • mt8365
  • mt6891
  • mt8696
  • mt6765
  • mt6877
  • mt6785
  • mt8667
  • mt6739
  • mt6761
  • mt6771
  • mt6580

google

  • android
CWE
CWE-755

Improper Handling of Exceptional Conditions