CVE-2024-20138
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
In wlan driver, there is a possible out of bound read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998291; Issue ID: MSV-1604.
Affected (4)
Products: Google: Android · Mediatek: Software Development Kit
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 13.0 | |
| Up to 3.3 |
| Running on/with | Platform Versions |
|---|---|
Mediatek Mt3605 | All versions |
Mediatek Mt6985 | All versions |
Mediatek Mt6989 | All versions |
Mediatek Mt6990 | All versions |
Mediatek Mt7925 | All versions |
Mediatek Mt7927 | All versions |
Mediatek Mt8195 | All versions |
Mediatek Mt8370 | All versions |
Mediatek Mt8390 | All versions |
References (1)
Source: security@mediatek.com
Vendor Advisory
Timeline
No history available yet.