← All CVEs

CVE-2020-0069

high · 7.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2021-11-03Remediation due 2022-05-03

In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-147882143References: M-ALPS04356754

7.8
CVSS
1.4%
EPSS (exploit prob.)
71st
EPSS percentile
2020-03-10
Published

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-787

Affected products

VendorProductAffected versions
googleandroidall versions
huaweiberkeley-l09_firmware< 10.0.0.177\(c10e3r1p4\)
huaweiberkeley-l09all versions
huaweicolumbia-al10b_firmware< 10.0.0.178\(c00e178r1p4\)
huaweicolumbia-al10ball versions
huaweicolumbia-l29d_firmware< 10.0.0.177\(c10e4r1p4\)
huaweicolumbia-l29dall versions
huaweicolumbia-tl00b_firmware< 10.0.0.178\(c01e178r1p4\)
huaweicolumbia-tl00ball versions
huaweicolumbia-tl00d_firmware< 10.0.0.178\(c01e178r1p4\)
huaweicolumbia-tl00dall versions
huaweicornell-al00a_firmware< 9.1.0.340\(c00e333r1p1t8\)
huaweicornell-al00aall versions
huaweicornell-tl10b_firmware< 9.1.0.340\(c01e333r1p1t8\)
huaweicornell-tl10ball versions
huaweidura-al00a_firmware< 1.0.0.190\(c00\)
huaweidura-al00aall versions
huaweihonor_20_pro_firmware< 10.0.0.194\(c636e3r3p1\)
huaweihonor_20_proall versions
huaweiy6_2019_firmware< 9.1.0.290\(c185e5r4p1\)
huaweiy6_2019all versions
huaweinova_3_firmware< 9.1.0.338\(c00e333r1p1t8\)
huaweinova_3all versions
huaweinova_4_firmware< 10.0.0.160\(c01e32r2p4\)
huaweinova_4all versions
huaweihonor_8a_firmware< 9.1.0.291\(c185e3r4p1\)
huaweihonor_8aall versions
huaweihonor_view_20_firmware< 10.0.0.198\(c432e10r3p4\)
huaweihonor_view_20all versions
huaweijakarta-al00a_firmware< 9.1.0.251\(c00e106r2p2\)
huaweijakarta-al00aall versions
huaweikatyusha-al00a_firmware< 9.1.0.146\(c00e131r2p2\)
huaweikatyusha-al00aall versions
huaweikatyusha-al10a_firmware< 9.1.0.160\(c00e150r1p7\)
huaweikatyusha-al10aall versions
huaweimadrid-al00a_firmware< 9.1.0.261\(c00e120r4p1\)
huaweimadrid-al00aall versions
huaweiparis-l29b_firmware< 9.1.0.380\(c636e1r1p3t8\)
huaweiparis-l29ball versions
huaweiprinceton-al10b_firmware< 10.0.0.194\(c00e61r4p11\)

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-0069