Vulnerabilidades em MediaTek, Inc.

998 resultados
Análise Vexday

Com 957 CVEs catalogadas, o histórico de vulnerabilidades da MediaTek, Inc. é extenso, embora a taxa de exploração ativa registrada esteja abaixo da média geral do catálogo CISA KEV — nenhuma CVE confirmada em exploração ativa no momento. O ponto de maior atenção é CVE-2024-20017, classificada como a vulnerabilidade mais perigosa no portfólio atual, com score EPSS de 0,4633, indicando probabilidade relevante de exploração em curto prazo. O tipo de falha mais recorrente é CWE-787 (escrita fora dos limites de memória), padrão que historicamente favorece execução de código arbitrário e eleva o risco de impacto crítico quando explorado. Com 30 CVEs de severidade crítica e 2 com PoC pública disponível, equipes responsáveis por dispositivos baseados em chipsets MediaTek devem priorizar a triagem dessas vulnerabilidades, especialmente as que combinam alta criticidade com código de prova de conceito acessível.

CVE-2024-20017CRITICALIn wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no EPSS 46.3%CVE-2024-20154HIGHIn Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution, if a UE has conneEPSS 3.9%CVE-2022-21744In Modem 2G RR, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decodinEPSS 3.1%CVE-2022-20083In Modem 2G/3G CC, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decoEPSS 2.5%CVE-2021-31574CRITICALIn Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilegeEPSS 1.7%CVE-2021-31575CRITICALIn Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilegeEPSS 1.7%CVE-2021-31573CRITICALIn Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilegeEPSS 1.7%CVE-2022-32663HIGHIn Wi-Fi driver, there is a possible system crash due to null pointer dereference. This could lead to remote denial of service with no additEPSS 1.6%CVE-2022-32665CRITICALIn Boa, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege with no adEPSS 1.5%CVE-2022-26437In httpclient, there is a possible out of bounds write due to uninitialized data. This could lead to remote escalation of privilege with no EPSS 1.4%CVE-2023-32845In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malEPSS 1.4%CVE-2023-32841In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malEPSS 1.4%CVE-2023-32843HIGHIn 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malEPSS 1.4%CVE-2024-20082CRITICALIn Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote code execution with no additional eEPSS 1.4%CVE-2023-32844In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malEPSS 1.4%CVE-2023-32842In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malEPSS 1.4%CVE-2023-32846In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malEPSS 1.4%CVE-2021-31578In Boa, there is a possible escalation of privilege due to a stack buffer overflow. This could lead to remote escalation of privilege from aEPSS 1.3%CVE-2024-20137HIGHIn wlan driver, there is a possible client disconnection due to improper handling of exceptional conditions. This could lead to remote deniaEPSS 1.2%CVE-2024-20004HIGHIn Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of service, if NW sent EPSS 1.2%