In V5 DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291215; Issue ID: MSV-2052.
History

Tue, 04 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 02:45:00 +0000

Type Values Removed Values Added
Description In V5 DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291215; Issue ID: MSV-2052.
Weaknesses CWE-125
References

cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published: 2025-03-03T02:25:48.870Z

Updated: 2025-03-04T16:11:22.574Z

Reserved: 2024-11-01T01:21:50.366Z

Link: CVE-2025-20652

cve-icon Vulnrichment

Updated: 2025-03-04T16:11:17.609Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-03-03T03:15:10.060

Modified: 2025-03-04T17:15:17.497

Link: CVE-2025-20652

cve-icon Redhat

No data.