SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-12485

The frame touch module does not make validity judgments on parameter lengths when processing specific parameters,which caused out of the boundary when memory access.The vulnerability eventually leads to a local DOS on the device.

MEDIUM 5.5EPSS 0.27%

Does this matter?

Lower severity and a low EPSS score (0.27%). Track it; it rarely justifies an emergency change on its own.

Description

The frame touch module does not make validity judgments on parameter lengths when processing specific parameters,which caused out of the boundary when memory access.The vulnerability eventually leads to a local DOS on the device.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS
0.27% probability · 19th percentile
CISA KEV
Not listed
Weakness
CWE-125
Affected
vivo/frame touch module
Source
security@vivo.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.