CVE-2020-0069 is an out-of-bounds write vulnerability in the Mediatek Command Queue driver affecting Android kernels, specifically impacting Google and Huawei devices. This flaw allows for local escalation of privilege without requiring user interaction or additional execution privileges. Rated as High severity (CVSS 7.8), it carries a significant risk due to its low attack complexity and potential for complete compromise of confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, as indicated by its presence in the KEV catalog and extensive media coverage, despite a lack of public exploit code on platforms like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* | ||
< 10.0.0.177\(c10e3r1p4\)CPE matchmatch criteria | cpe:2.3:o:huawei:berkeley-l09_firmware:*:*:*:*:*:*:*:* | ||
< 10.0.0.178\(c00e178r1p4\)CPE matchmatch criteria | cpe:2.3:o:huawei:columbia-al10b_firmware:*:*:*:*:*:*:*:* | ||
< 10.0.0.177\(c10e4r1p4\)CPE matchmatch criteria | cpe:2.3:o:huawei:columbia-l29d_firmware:*:*:*:*:*:*:*:* | ||
< 10.0.0.178\(c01e178r1p4\)CPE matchmatch criteria | cpe:2.3:o:huawei:columbia-tl00b_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.