
Cloud Vulnerability DB
A community-led vulnerabilities database
In memory management driver, there is a possible system crash due to improper input validation. This vulnerability (CVE-2021-0417) affects Android versions 10.0 and 11.0 across multiple MediaTek chipsets. The vulnerability was disclosed in August 2021 and has been assigned a CVSS v3.1 base score of 5.5 (Medium) (NVD, MediaTek Bulletin).
The vulnerability is classified as CWE-330 (Use of Insufficiently Random Values) and CWE-20 (Improper Input Validation) in the memory management driver. The CVSS vector string is CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, indicating local access, low attack complexity, and high impact on availability (NVD).
The vulnerability could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation, making it a significant risk for affected systems (MediaTek Bulletin).
MediaTek has released patches for the affected chipsets. Device OEMs were notified of the issues and corresponding security patches at least a month before the public disclosure. Users should ensure their devices are updated with the latest security patches (MediaTek Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."