CVE Feed

    Dashboard / CVE / CVE-2019-15027

    CVE-2019-15027

    The MediaTek Embedded Multimedia Card (eMMC) subsystem for Android on MT65xx, MT66xx, and MT8163 SoC devices allows attackers to execute arbitrary commands as root via shell metacharacters in a filename under /data, because clear_emmc_nomedia_entry in platform/mt6577/external/meta/emmc/meta_clr_emmc.c invokes 'system("/system/bin/rm -r /data/' followed by this filename upon an eMMC clearance from a Meta Mode boot. NOTE: compromise of Fire OS on the Amazon Echo Dot would require a second hypothetical vulnerability that allows creation of the required file under /data.

    Published:Aug 14, 2019
    Last Modified:Nov 21, 2024
    EPS:Aug 14, 2019
    EPSS Score:0.02356
    CVSS Score:9.8

    Affected Products

    Vendor
    Mediatek
    Product
    Mt6577
    Vendor
    Mediatek
    Product
    Mt6577 Firmware
    Vendor
    Mediatek
    Product
    Mt6625
    Vendor
    Mediatek
    Product
    Mt6625 Firmware
    Vendor
    Mediatek
    Product
    Mt8163
    Vendor
    Mediatek
    Product
    Mt8163 Firmware

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High