In Wi-Fi driver, there is a possible undefined behavior due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: GN20220705059; Issue ID: GN20220705059.
References
Link | Resource |
---|---|
https://corp.mediatek.com/product-security-bulletin/January-2023 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
History
08 Aug 2023, 14:22
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-755 |
10 Jan 2023, 03:33
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-20 | |
CPE | cpe:2.3:h:mediatek:mt7916:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7603:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7981:-:*:*:*:*:*:*:* cpe:2.3:o:mediatek:mt7916_firmware:7.6.6.0:*:*:*:*:*:*:* cpe:2.3:o:mediatek:mt7628_firmware:7.6.6.0:*:*:*:*:*:*:* cpe:2.3:o:mediatek:mt7915_firmware:7.6.6.0:*:*:*:*:*:*:* cpe:2.3:o:mediatek:mt7986_firmware:7.6.6.0:*:*:*:*:*:*:* cpe:2.3:o:mediatek:mt7613_firmware:7.6.6.0:*:*:*:*:*:*:* cpe:2.3:o:mediatek:mt7629_firmware:7.6.6.0:*:*:*:*:*:*:* cpe:2.3:o:mediatek:mt7981_firmware:7.6.6.0:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7613:-:*:*:*:*:*:*:* cpe:2.3:o:mediatek:mt7615_firmware:7.6.6.0:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7915:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7986:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7622:-:*:*:*:*:*:*:* cpe:2.3:o:mediatek:mt7622_firmware:7.6.6.0:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7629:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7615:-:*:*:*:*:*:*:* cpe:2.3:o:mediatek:mt7603_firmware:7.6.6.0:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7628:-:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.7 |
First Time |
Mediatek mt7603
Mediatek mt7628 Firmware Mediatek mt7916 Mediatek mt7916 Firmware Mediatek mt7622 Firmware Mediatek mt7628 Mediatek mt7981 Firmware Mediatek mt7629 Firmware Mediatek mt7915 Mediatek mt7986 Firmware Mediatek mt7603 Firmware Mediatek mt7615 Firmware Mediatek mt7622 Mediatek Mediatek mt7629 Mediatek mt7613 Firmware Mediatek mt7613 Mediatek mt7915 Firmware Mediatek mt7986 Mediatek mt7615 Mediatek mt7981 |
|
References | (MISC) https://corp.mediatek.com/product-security-bulletin/January-2023 - Vendor Advisory |
03 Jan 2023, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-01-03 21:15
Updated : 2023-12-10 14:48
NVD link : CVE-2022-32658
Mitre link : CVE-2022-32658
CVE.ORG link : CVE-2022-32658
JSON object : View
Products Affected
mediatek
- mt7915_firmware
- mt7629
- mt7613_firmware
- mt7622
- mt7986
- mt7981
- mt7916_firmware
- mt7615_firmware
- mt7622_firmware
- mt7603
- mt7916
- mt7915
- mt7615
- mt7628_firmware
- mt7981_firmware
- mt7986_firmware
- mt7613
- mt7628
- mt7603_firmware
- mt7629_firmware
CWE
CWE-755
Improper Handling of Exceptional Conditions