CVE-2024-20072
6.6
Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.7 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00364732; Issue ID: MSV-1332.
Affected (4)
Products: Mediatek: Software Development Kit · Openwrt: Openwrt
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.0.5.0 | |
| Version 19.07.0 |
| Running on/with | Platform Versions |
|---|---|
Mediatek Mt6890 | All versions |
Mediatek Mt6990 | All versions |
Mediatek Mt7622 | All versions |
References (2)
Source: security@mediatek.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.