CVE-2024-20103
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09001358; Issue ID: MSV-1599.
Affected (4)
Products: Google: Android · Mediatek: Software Development Kit
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 13.0 | |
| Up to 3.3 |
| Running on/with | Platform Versions |
|---|---|
Mediatek Mt3605 | All versions |
Mediatek Mt6985 | All versions |
Mediatek Mt6989 | All versions |
Mediatek Mt6990 | All versions |
Mediatek Mt7927 | All versions |
Mediatek Mt8183 | All versions |
Mediatek Mt8512 | All versions |
Mediatek Mt8678 | All versions |
Mediatek Mt8695 | All versions |
Mediatek Mt8698 | All versions |
Mediatek Mt8796 | All versions |
Mediatek Mt8893 | All versions |
References (1)
Source: security@mediatek.com
Vendor Advisory
Timeline
No history available yet.