CVE-2024-20153
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08990446 / ALPS09057442; Issue ID: MSV-1598.
Affected (6)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 14.0 | |
| Version 3.3 | |
| Up to 3.5 |
| Running on/with | Platform Versions |
|---|---|
Mediatek Mt2737 | All versions |
Mediatek Mt6989 | All versions |
Mediatek Mt6991 | All versions |
Mediatek Mt7925 | All versions |
Mediatek Mt8365 | All versions |
Mediatek Mt8518s | All versions |
Mediatek Mt8532 | All versions |
Mediatek Mt8666 | All versions |
Mediatek Mt8667 | All versions |
Mediatek Mt8673 | All versions |
Mediatek Mt8676 | All versions |
Mediatek Mt8678 | All versions |
Mediatek Mt8755 | All versions |
Mediatek Mt8766 | All versions |
Mediatek Mt8768 | All versions |
Mediatek Mt8775 | All versions |
Mediatek Mt8781 | All versions |
Mediatek Mt8786 | All versions |
Mediatek Mt8788 | All versions |
Mediatek Mt8796 | All versions |
Mediatek Mt8798 | All versions |
Mediatek Mt8893 | All versions |
References (1)
Source: security@mediatek.com
Vendor Advisory
Timeline
No history available yet.