CVE-2023-32871
In DA, there is a possible permission bypass due to an incorrect status check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08355514; Issue ID: ALPS08355514.
Scoring
- CVSS base score
- 0
- EPSS probability
- 0.00%
- CWE
- CWE-391
- Published
- 2024-05-06
- Last modified
- 2026-03-13
Affected products
- MediaTek, Inc. MT2737, MT6739, MT6761, MT6765, MT6768, MT6771, MT6779, MT6781, MT6785, MT6789, MT6833, MT6835, MT6853, MT6853T, MT6855, MT6873, MT6877, MT6879, MT6880, MT6883, MT6885, MT6886, MT6889, MT6890, MT6893, MT6895, MT6897, MT6980, MT6983, MT6985, MT6989, MT6990, MT8167, MT8167S, MT8168, MT8173, MT8175, MT8185, MT8188, MT8195, MT8321, MT8362A, MT8365, MT8385, MT8390, MT8395, MT8755, MT8765, MT8766, MT8768, MT8775, MT8781, MT8786, MT8788, MT8789, MT8791, MT8791T, MT8797, MT8798
Weakness type
Related vulnerabilities
- CVE-2026-74900 — openssl_encrypt before 1.4.0 Weak Shared Secret via PQC Simulation Mode
- CVE-2025-71325 — picklescan - Detection Bypass via STACK_GLOBAL Opcode Parsing Logic Flaw
- CVE-2024-52316 — Apache Tomcat: Authentication bypass when using Jakarta Authentication API
- CVE-2022-20849 — Cisco IOS XR Software Broadband Network Gateway PPPoE Denial of Service Vulnerability
- CVE-2024-23326 — Envoy incorrectly accepts HTTP 200 response for entering upgrade mode
- CVE-2023-0572 — Unchecked Error Condition in froxlor/froxlor
- CVE-2022-22160 — Junos OS: MX Series: The bbe-smgd process crashes if an unsupported configuration exists and a PPPoE client sends a specific message
- CVE-2020-14383 — A flaw was found in samba's DNS server. An authenticated user could use this flaw to the RPC server...