Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-13331 | In scp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09625562; Issue ID: MSV-3027. |
| Link | Providers |
|---|---|
| https://corp.mediatek.com/product-security-bulletin/May-2025 |
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 07 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
ssvc
|
Tue, 06 May 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google android Mediatek Mediatek mt6878 Mediatek mt6897 Mediatek mt6899 Mediatek mt6989 Mediatek mt6991 Mediatek mt8775 Mediatek mt8796 |
|
| CPEs | cpe:2.3:h:mediatek:mt6878:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6897:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6899:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6989:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6991:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8775:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8796:-:*:*:*:*:*:*:* cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Google
Google android Mediatek Mediatek mt6878 Mediatek mt6897 Mediatek mt6899 Mediatek mt6989 Mediatek mt6991 Mediatek mt8775 Mediatek mt8796 |
|
| Metrics |
cvssV3_1
|
Mon, 05 May 2025 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In scp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09625562; Issue ID: MSV-3027. | |
| Weaknesses | CWE-787 | |
| References |
|
Status: PUBLISHED
Assigner: MediaTek
Published:
Updated: 2026-02-26T18:29:03.746Z
Reserved: 2024-11-01T01:21:50.370Z
Link: CVE-2025-20668
Updated: 2025-05-07T14:56:55.820Z
Status : Modified
Published: 2025-05-05T03:15:22.180
Modified: 2025-05-07T15:15:56.780
Link: CVE-2025-20668
No data.
OpenCVE Enrichment
No data.
EUVD