PT-2021-5738 · Mediatek · Mediatek Microchips
Published
2021-12-25
·
Updated
2022-01-10
·
CVE-2021-37561
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
MediaTek microchips versions 7.4.0.0
MediaTek microchips (affected versions not specified), specifically chipsets MT7603E, MT7610, MT7612, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, MT7915
Description
The issue is related to the mishandling of the WPS (Wi-Fi Protected Setup) protocol and an out-of-bounds write in the Wi-Fi driver software of MediaTek microchips. This can allow a remote attacker to elevate their privileges. The vulnerability is associated with a buffer overflow in memory.
Recommendations
For version 7.4.0.0, update to a newer version that addresses the mishandling of the WPS protocol and the out-of-bounds write issue.
For other affected versions of MediaTek microchips, specifically chipsets MT7603E, MT7610, MT7612, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, MT7915, restrict access to the WPS protocol until a patch is available.
As a temporary workaround, consider disabling the WPS protocol in affected devices until the issue is resolved.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mediatek Microchips