Risk | Low |
Patch available | YES |
Number of vulnerabilities | 19 |
CVE-ID | CVE-2021-0415 CVE-2021-0628 CVE-2021-0627 CVE-2021-0626 CVE-2021-0420 CVE-2021-0419 CVE-2021-0418 CVE-2021-0417 CVE-2021-0416 CVE-2021-0408 CVE-2021-0573 CVE-2021-0407 CVE-2021-0582 CVE-2021-0581 CVE-2021-0580 CVE-2021-0579 CVE-2021-0578 CVE-2021-0576 CVE-2021-0574 |
CWE-ID | CWE-200 CWE-20 CWE-190 CWE-787 CWE-400 CWE-330 CWE-703 CWE-123 CWE-125 CWE-191 CWE-126 CWE-122 |
Exploitation vector | Local |
Public exploit | N/A |
Vulnerable software |
MT6580 Mobile applications / Mobile firmware & hardware MT6582E Mobile applications / Mobile firmware & hardware MT6582H Mobile applications / Mobile firmware & hardware MT6582T Mobile applications / Mobile firmware & hardware MT6582W Mobile applications / Mobile firmware & hardware MT6582_90 Mobile applications / Mobile firmware & hardware MT6589 Mobile applications / Mobile firmware & hardware MT6589TD Mobile applications / Mobile firmware & hardware MT6592E Mobile applications / Mobile firmware & hardware MT6592H Mobile applications / Mobile firmware & hardware MT6592T Mobile applications / Mobile firmware & hardware MT6592W Mobile applications / Mobile firmware & hardware MT6592_90 Mobile applications / Mobile firmware & hardware MT6595 Mobile applications / Mobile firmware & hardware MT6731 Mobile applications / Mobile firmware & hardware MT6732 Mobile applications / Mobile firmware & hardware MT6735 Mobile applications / Mobile firmware & hardware MT6737 Mobile applications / Mobile firmware & hardware MT6739 Mobile applications / Mobile firmware & hardware MT6750 Mobile applications / Mobile firmware & hardware MT6750S Mobile applications / Mobile firmware & hardware MT6752 Mobile applications / Mobile firmware & hardware MT6753 Mobile applications / Mobile firmware & hardware MT6755 Mobile applications / Mobile firmware & hardware MT6755S Mobile applications / Mobile firmware & hardware MT6757 Mobile applications / Mobile firmware & hardware MT6757C Mobile applications / Mobile firmware & hardware MT6757CD Mobile applications / Mobile firmware & hardware MT6757CH Mobile applications / Mobile firmware & hardware MT6758 Mobile applications / Mobile firmware & hardware MT6761 Mobile applications / Mobile firmware & hardware MT6762 Mobile applications / Mobile firmware & hardware MT6763 Mobile applications / Mobile firmware & hardware MT6765 Mobile applications / Mobile firmware & hardware MT6768 Mobile applications / Mobile firmware & hardware MT6769 Mobile applications / Mobile firmware & hardware MT6771 Mobile applications / Mobile firmware & hardware MT6795 Mobile applications / Mobile firmware & hardware MT6797 Mobile applications / Mobile firmware & hardware MT6799 Mobile applications / Mobile firmware & hardware MT6833 Mobile applications / Mobile firmware & hardware MT6570 Mobile applications / Mobile firmware & hardware MT6779 Hardware solutions / Firmware MT6785 Hardware solutions / Firmware MT6853 Hardware solutions / Firmware MT6853T Hardware solutions / Firmware MT6873 Hardware solutions / Firmware MT6875 Hardware solutions / Firmware MT6877 Hardware solutions / Firmware MT6883 Hardware solutions / Firmware MT6885 Hardware solutions / Firmware MT6889 Hardware solutions / Firmware MT6891 Hardware solutions / Firmware MT6893 Hardware solutions / Firmware |
Vendor | MediaTek |
Security Bulletin
This security bulletin contains information about 19 vulnerabilities.
EUVDB-ID: #VU72921
Risk: Low
CVSSv4.0: 1.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2021-0415
CWE-ID:
CWE-200 - Information exposure
Exploit availability: No
DescriptionThe vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a missing permission check within memory management driver. A local application can gain access to sensitive information.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6580: All versions
MT6582E: All versions
MT6582H: All versions
MT6582T: All versions
MT6582W: All versions
MT6582_90: All versions
MT6589: All versions
MT6589TD: All versions
MT6592E: All versions
MT6592H: All versions
MT6592T: All versions
MT6592W: All versions
MT6592_90: All versions
MT6595: All versions
MT6731: All versions
MT6732: All versions
MT6735: All versions
MT6737: All versions
MT6739: All versions
MT6750: All versions
MT6750S: All versions
MT6752: All versions
MT6753: All versions
MT6755: All versions
MT6755S: All versions
MT6757: All versions
MT6757C: All versions
MT6757CD: All versions
MT6757CH: All versions
MT6758: All versions
MT6761: All versions
MT6762: All versions
MT6763: All versions
MT6765: All versions
MT6768: All versions
MT6769: All versions
MT6771: All versions
MT6779: All versions
MT6785: All versions
MT6795: All versions
MT6797: All versions
MT6799: All versions
MT6833: All versions
MT6853: All versions
MT6853T: All versions
MT6873: All versions
MT6875: All versions
MT6877: All versions
MT6883: All versions
MT6885: All versions
MT6889: All versions
MT6891: All versions
MT6893: All versions
CPE2.3https://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72929
Risk: Low
CVSSv4.0: 5.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2021-0628
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to improper input validation within OMA DRM. A local privileged application can execute arbitrary code.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6580: All versions
MT6735: All versions
MT6739: All versions
MT6755S: All versions
MT6757: All versions
MT6761: All versions
MT6763: All versions
MT6765: All versions
MT6768: All versions
MT6771: All versions
MT6779: All versions
MT6785: All versions
MT6833: All versions
MT6853: All versions
MT6873: All versions
MT6877: All versions
MT6885: All versions
CPE2.3https://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72928
Risk: Low
CVSSv4.0: 5.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2021-0627
CWE-ID:
CWE-190 - Integer overflow
Exploit availability: No
DescriptionThe vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to an integer overflow within OMA DRM. A local privileged application can execute arbitrary code.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6580: All versions
MT6735: All versions
MT6739: All versions
MT6755S: All versions
MT6757: All versions
MT6761: All versions
MT6763: All versions
MT6765: All versions
MT6768: All versions
MT6771: All versions
MT6785: All versions
MT6833: All versions
MT6853: All versions
MT6873: All versions
MT6877: All versions
MT6885: All versions
CPE2.3https://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72927
Risk: Low
CVSSv4.0: 5.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2021-0626
CWE-ID:
CWE-787 - Out-of-bounds write
Exploit availability: No
DescriptionThe vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to a missing bounds check within ged. A local privileged application can execute arbitrary code.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6768: All versions
MT6771: All versions
MT6779: All versions
MT6785: All versions
CPE2.3https://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72926
Risk: Low
CVSSv4.0: 1.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2021-0420
CWE-ID:
CWE-400 - Resource exhaustion
Exploit availability: No
DescriptionThe vulnerability allows a local application to perform service disruption.
The vulnerability exists due to a missing bounds check within memory management driver. A local application can perform service disruption.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6580: All versions
MT6582E: All versions
MT6582H: All versions
MT6582T: All versions
MT6582W: All versions
MT6582_90: All versions
MT6589: All versions
MT6589TD: All versions
MT6592E: All versions
MT6592H: All versions
MT6592T: All versions
MT6592W: All versions
MT6592_90: All versions
MT6595: All versions
MT6731: All versions
MT6732: All versions
MT6735: All versions
MT6737: All versions
MT6739: All versions
MT6750: All versions
MT6750S: All versions
MT6752: All versions
MT6753: All versions
MT6755: All versions
MT6755S: All versions
MT6757: All versions
MT6757C: All versions
MT6757CD: All versions
MT6757CH: All versions
MT6758: All versions
MT6761: All versions
MT6762: All versions
MT6763: All versions
MT6765: All versions
MT6768: All versions
MT6769: All versions
MT6771: All versions
MT6779: All versions
MT6785: All versions
MT6795: All versions
MT6797: All versions
MT6799: All versions
MT6833: All versions
MT6853: All versions
MT6853T: All versions
MT6873: All versions
MT6875: All versions
MT6877: All versions
MT6883: All versions
MT6885: All versions
MT6889: All versions
MT6891: All versions
MT6893: All versions
CPE2.3https://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72925
Risk: Low
CVSSv4.0: 1.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2021-0419
CWE-ID:
CWE-400 - Resource exhaustion
Exploit availability: No
DescriptionThe vulnerability allows a local application to perform service disruption.
The vulnerability exists due to improper input validation within memory management driver. A local application can perform service disruption.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6580: All versions
MT6582E: All versions
MT6582H: All versions
MT6582T: All versions
MT6582W: All versions
MT6582_90: All versions
MT6589: All versions
MT6589TD: All versions
MT6592E: All versions
MT6592H: All versions
MT6592T: All versions
MT6592W: All versions
MT6592_90: All versions
MT6595: All versions
MT6731: All versions
MT6732: All versions
MT6735: All versions
MT6737: All versions
MT6739: All versions
MT6750: All versions
MT6750S: All versions
MT6752: All versions
MT6753: All versions
MT6755: All versions
MT6755S: All versions
MT6757: All versions
MT6757C: All versions
MT6757CD: All versions
MT6757CH: All versions
MT6758: All versions
MT6761: All versions
MT6762: All versions
MT6763: All versions
MT6765: All versions
MT6768: All versions
MT6769: All versions
MT6771: All versions
MT6779: All versions
MT6785: All versions
MT6795: All versions
MT6797: All versions
MT6799: All versions
MT6833: All versions
MT6853: All versions
MT6853T: All versions
MT6873: All versions
MT6875: All versions
MT6877: All versions
MT6883: All versions
MT6885: All versions
MT6889: All versions
MT6891: All versions
MT6893: All versions
CPE2.3https://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72924
Risk: Low
CVSSv4.0: 1.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2021-0418
CWE-ID:
CWE-400 - Resource exhaustion
Exploit availability: No
DescriptionThe vulnerability allows a local application to perform service disruption.
The vulnerability exists due to improper input validation within memory management driver. A local application can perform service disruption.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6580: All versions
MT6582E: All versions
MT6582H: All versions
MT6582T: All versions
MT6582W: All versions
MT6582_90: All versions
MT6589: All versions
MT6589TD: All versions
MT6592E: All versions
MT6592H: All versions
MT6592T: All versions
MT6592W: All versions
MT6592_90: All versions
MT6595: All versions
MT6731: All versions
MT6732: All versions
MT6735: All versions
MT6737: All versions
MT6739: All versions
MT6750: All versions
MT6750S: All versions
MT6752: All versions
MT6753: All versions
MT6755: All versions
MT6755S: All versions
MT6757: All versions
MT6757C: All versions
MT6757CD: All versions
MT6757CH: All versions
MT6758: All versions
MT6761: All versions
MT6762: All versions
MT6763: All versions
MT6765: All versions
MT6768: All versions
MT6769: All versions
MT6771: All versions
MT6779: All versions
MT6785: All versions
MT6795: All versions
MT6797: All versions
MT6799: All versions
MT6833: All versions
MT6853: All versions
MT6853T: All versions
MT6873: All versions
MT6875: All versions
MT6877: All versions
MT6883: All versions
MT6885: All versions
MT6889: All versions
MT6891: All versions
MT6893: All versions
CPE2.3https://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72923
Risk: Low
CVSSv4.0: 1.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2021-0417
CWE-ID:
CWE-330 - Use of Insufficiently Random Values
Exploit availability: No
DescriptionThe vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improper input validation within memory management driver. A local application can gain access to sensitive information.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6580: All versions
MT6582E: All versions
MT6582H: All versions
MT6582T: All versions
MT6582W: All versions
MT6582_90: All versions
MT6589: All versions
MT6589TD: All versions
MT6592E: All versions
MT6592H: All versions
MT6592T: All versions
MT6592W: All versions
MT6592_90: All versions
MT6595: All versions
MT6731: All versions
MT6732: All versions
MT6735: All versions
MT6737: All versions
MT6739: All versions
MT6750: All versions
MT6750S: All versions
MT6752: All versions
MT6753: All versions
MT6755: All versions
MT6755S: All versions
MT6757: All versions
MT6757C: All versions
MT6757CD: All versions
MT6757CH: All versions
MT6758: All versions
MT6761: All versions
MT6762: All versions
MT6763: All versions
MT6765: All versions
MT6768: All versions
MT6769: All versions
MT6771: All versions
MT6779: All versions
MT6785: All versions
MT6795: All versions
MT6797: All versions
MT6799: All versions
MT6833: All versions
MT6853: All versions
MT6853T: All versions
MT6873: All versions
MT6875: All versions
MT6877: All versions
MT6883: All versions
MT6885: All versions
MT6889: All versions
MT6891: All versions
MT6893: All versions
CPE2.3https://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72922
Risk: Low
CVSSv4.0: 1.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2021-0416
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improper input validation within memory management driver. A local application can gain access to sensitive information.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6580: All versions
MT6582E: All versions
MT6582H: All versions
MT6582T: All versions
MT6582W: All versions
MT6582_90: All versions
MT6589: All versions
MT6589TD: All versions
MT6592E: All versions
MT6592H: All versions
MT6592T: All versions
MT6592W: All versions
MT6592_90: All versions
MT6595: All versions
MT6731: All versions
MT6732: All versions
MT6735: All versions
MT6737: All versions
MT6739: All versions
MT6750: All versions
MT6750S: All versions
MT6752: All versions
MT6753: All versions
MT6755: All versions
MT6755S: All versions
MT6757: All versions
MT6757C: All versions
MT6757CD: All versions
MT6757CH: All versions
MT6758: All versions
MT6761: All versions
MT6762: All versions
MT6763: All versions
MT6765: All versions
MT6768: All versions
MT6769: All versions
MT6771: All versions
MT6779: All versions
MT6785: All versions
MT6795: All versions
MT6797: All versions
MT6799: All versions
MT6833: All versions
MT6853: All versions
MT6853T: All versions
MT6873: All versions
MT6875: All versions
MT6877: All versions
MT6883: All versions
MT6885: All versions
MT6889: All versions
MT6891: All versions
MT6893: All versions
CPE2.3https://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72920
Risk: Low
CVSSv4.0: 1.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2021-0408
CWE-ID:
CWE-703 - Improper Check or Handling of Exceptional Conditions
Exploit availability: No
DescriptionThe vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to an incorrect bounds check within asf extractor. A local application can gain access to sensitive information.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6570: All versions
MT6580: All versions
MT6735: All versions
MT6737: All versions
MT6739: All versions
MT6750: All versions
MT6750S: All versions
MT6753: All versions
MT6755: All versions
MT6755S: All versions
MT6757: All versions
MT6757C: All versions
MT6757CD: All versions
MT6757CH: All versions
MT6758: All versions
MT6761: All versions
MT6762: All versions
MT6763: All versions
MT6765: All versions
MT6768: All versions
MT6771: All versions
MT6779: All versions
MT6785: All versions
MT6797: All versions
MT6799: All versions
MT6833: All versions
MT6853: All versions
MT6853T: All versions
MT6873: All versions
MT6877: All versions
MT6885: All versions
MT6889: All versions
MT6893: All versions
CPE2.3https://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72911
Risk: Low
CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2021-0573
CWE-ID:
CWE-703 - Improper Check or Handling of Exceptional Conditions
Exploit availability: No
DescriptionThe vulnerability allows a local application to execute arbitrary code.
The vulnerability exists due to a missing bounds check within asf extractor. A local application can execute arbitrary code.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6570: All versions
MT6580: All versions
MT6735: All versions
MT6737: All versions
MT6739: All versions
MT6750: All versions
MT6750S: All versions
MT6753: All versions
MT6755: All versions
MT6755S: All versions
MT6757: All versions
MT6757C: All versions
MT6757CD: All versions
MT6757CH: All versions
MT6758: All versions
MT6761: All versions
MT6762: All versions
MT6763: All versions
MT6765: All versions
MT6768: All versions
MT6771: All versions
MT6779: All versions
MT6785: All versions
MT6797: All versions
MT6799: All versions
MT6833: All versions
MT6853: All versions
MT6853T: All versions
MT6873: All versions
MT6877: All versions
MT6885: All versions
MT6889: All versions
MT6893: All versions
CPE2.3https://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72919
Risk: Low
CVSSv4.0: 5.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2021-0407
CWE-ID:
CWE-123 - Write-what-where Condition
Exploit availability: No
DescriptionThe vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to an incorrect bounds check within clk driver. A local privileged application can execute arbitrary code.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6739: All versions
MT6761: All versions
MT6762: All versions
MT6763: All versions
MT6765: All versions
MT6768: All versions
MT6769: All versions
MT6771: All versions
MT6833: All versions
MT6853: All versions
MT6853T: All versions
MT6873: All versions
MT6885: All versions
MT6889: All versions
MT6893: All versions
CPE2.3https://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72918
Risk: Low
CVSSv4.0: 1.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2021-0582
CWE-ID:
CWE-125 - Out-of-bounds read
Exploit availability: No
DescriptionThe vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a missing bounds check within wifi driver. A local application can gain access to sensitive information.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6761: All versions
MT6762: All versions
MT6765: All versions
MT6768: All versions
MT6779: All versions
MT6785: All versions
MT6833: All versions
MT6853: All versions
MT6873: All versions
MT6875: All versions
MT6877: All versions
MT6883: All versions
MT6885: All versions
MT6889: All versions
MT6891: All versions
MT6893: All versions
CPE2.3https://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72917
Risk: Low
CVSSv4.0: 1.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2021-0581
CWE-ID:
CWE-125 - Out-of-bounds read
Exploit availability: No
DescriptionThe vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a missing bounds check within wifi driver. A local application can gain access to sensitive information.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6761: All versions
MT6762: All versions
MT6765: All versions
MT6768: All versions
MT6779: All versions
MT6785: All versions
MT6833: All versions
MT6853: All versions
MT6873: All versions
MT6875: All versions
MT6877: All versions
MT6883: All versions
MT6885: All versions
MT6889: All versions
MT6891: All versions
MT6893: All versions
CPE2.3https://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72916
Risk: Low
CVSSv4.0: 1.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2021-0580
CWE-ID:
CWE-191 - Integer underflow
Exploit availability: No
DescriptionThe vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a missing bounds check within wifi driver. A local application can gain access to sensitive information.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6761: All versions
MT6762: All versions
MT6765: All versions
MT6768: All versions
MT6779: All versions
MT6785: All versions
MT6833: All versions
MT6853: All versions
MT6873: All versions
MT6875: All versions
MT6877: All versions
MT6883: All versions
MT6885: All versions
MT6889: All versions
MT6891: All versions
MT6893: All versions
CPE2.3https://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72915
Risk: Low
CVSSv4.0: 1.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2021-0579
CWE-ID:
CWE-126 - Buffer over-read
Exploit availability: No
DescriptionThe vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a missing bounds check within wifi driver. A local application can gain access to sensitive information.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6761: All versions
MT6762: All versions
MT6765: All versions
MT6768: All versions
MT6779: All versions
MT6785: All versions
MT6833: All versions
MT6853: All versions
MT6873: All versions
MT6875: All versions
MT6877: All versions
MT6883: All versions
MT6885: All versions
MT6889: All versions
MT6891: All versions
MT6893: All versions
CPE2.3https://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72914
Risk: Low
CVSSv4.0: 1.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2021-0578
CWE-ID:
CWE-125 - Out-of-bounds read
Exploit availability: No
DescriptionThe vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a missing bounds check within wifi driver. A local application can gain access to sensitive information.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6761: All versions
MT6762: All versions
MT6765: All versions
MT6768: All versions
MT6779: All versions
MT6785: All versions
MT6833: All versions
MT6853: All versions
MT6873: All versions
MT6875: All versions
MT6877: All versions
MT6883: All versions
MT6885: All versions
MT6889: All versions
MT6891: All versions
MT6893: All versions
CPE2.3https://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72913
Risk: Low
CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2021-0576
CWE-ID:
CWE-122 - Heap-based Buffer Overflow
Exploit availability: No
DescriptionThe vulnerability allows a local application to execute arbitrary code.
The vulnerability exists due to a missing bounds check within flv extractor. A local application can execute arbitrary code.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6570: All versions
MT6580: All versions
MT6735: All versions
MT6737: All versions
MT6739: All versions
MT6750: All versions
MT6750S: All versions
MT6753: All versions
MT6755: All versions
MT6755S: All versions
MT6757: All versions
MT6757C: All versions
MT6757CD: All versions
MT6757CH: All versions
MT6758: All versions
MT6761: All versions
MT6762: All versions
MT6763: All versions
MT6765: All versions
MT6768: All versions
MT6771: All versions
MT6779: All versions
MT6785: All versions
MT6797: All versions
MT6799: All versions
MT6833: All versions
MT6853: All versions
MT6853T: All versions
MT6873: All versions
MT6877: All versions
MT6885: All versions
MT6889: All versions
MT6893: All versions
CPE2.3https://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72912
Risk: Low
CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2021-0574
CWE-ID:
CWE-787 - Out-of-bounds write
Exploit availability: No
DescriptionThe vulnerability allows a local application to execute arbitrary code.
The vulnerability exists due to a missing bounds check within asf extractor. A local application can execute arbitrary code.
MitigationInstall security update from vendor's website.
Vulnerable software versionsMT6570: All versions
MT6580: All versions
MT6735: All versions
MT6737: All versions
MT6739: All versions
MT6750: All versions
MT6750S: All versions
MT6753: All versions
MT6755: All versions
MT6755S: All versions
MT6757: All versions
MT6757C: All versions
MT6757CD: All versions
MT6757CH: All versions
MT6758: All versions
MT6761: All versions
MT6762: All versions
MT6763: All versions
MT6765: All versions
MT6768: All versions
MT6771: All versions
MT6779: All versions
MT6785: All versions
MT6797: All versions
MT6799: All versions
MT6833: All versions
MT6853: All versions
MT6853T: All versions
MT6873: All versions
MT6877: All versions
MT6885: All versions
MT6889: All versions
MT6893: All versions
CPE2.3https://corp.mediatek.com/product-security-bulletin/August-2021
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.