Impact
The vulnerability resides in the ccci component of MediaTek chipsets, where a missing bounds check can trigger an out‑of‑bounds read (CWE‑125). This flaw can cause the system to become unresponsive in a local denial‑of‑service scenario, but it cannot be exploited remotely and requires the attacker to already hold System privilege. No user interaction is needed to trigger the failure, so any privileged process could inadvertently cause the crash.
Affected Systems
Affected systems are MediaTek chipsets running the ccci firmware component. No specific version information is listed in the advisory, so all implementations of ccci on MediaTek devices may potentially be vulnerable until patched.
Risk and Exploitability
The CVSS score is 4.4 and the EPSS score is less than 1%, but the flaw is not listed in the CISA KEV catalog, indicating that no publicly available exploitation code is known. Because the exploitation requires System privilege, the practical risk to unprivileged users is low. Nonetheless, once privilege is gained—for example, through a compromised application—an attacker could trigger the denial of service, causing service disruption to the affected device.
OpenCVE Enrichment