Lucene search

K
cveMediaTekCVE-2024-20054
HistoryApr 01, 2024 - 3:15 a.m.

CVE-2024-20054

2024-04-0103:15:08
CWE-787
MediaTek
web.nvd.nist.gov
38
cve
escalation of privilege
local execution
bounds check
patch id
issue id
nvd

CVSS3

6.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

6.9

Confidence

High

EPSS

0

Percentile

9.0%

In gnss, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08580200; Issue ID: ALPS08580200.

Affected configurations

Vulners
Node
googleandroidRange<13.0
OR
googleandroidRange<14.0
OR
mediatekmt2735_firmware
OR
mediatekmt2737_firmware
OR
mediatekmt6762_firmware
OR
mediatekmt6765_firmware
OR
mediatekmt6769_firmware
OR
mediatekmt6833_firmware
OR
mediatekmt6835_firmware
OR
mediatekmt6853_firmware
OR
mediatekmt6855_firmware
OR
mediatekmt6873_firmware
OR
mediatekmt6875_firmware
OR
mediatekmt6877_firmware
OR
mediatekmt6879_firmware
OR
mediatekmt6883_firmware
OR
mediatekmt6885_firmware
OR
mediatekmt6889_firmware
OR
mediatekmt6890_firmware
OR
mediatekmt6891_firmware
OR
mediatekmt6893_firmware
OR
mediatekmt6895_firmware
OR
mediatekmt6983_firmware
OR
mediatekmt6985_firmware
OR
mediatekmt6989_firmware
OR
mediatekmt6990_firmware
OR
mediatekmt8168_firmware
OR
mediatekmt8173_firmware
OR
mediatekmt8195_firmware
OR
mediatekmt8321_firmware
OR
mediatekmt8385_firmware
OR
mediatekmt8390_firmware
OR
mediatekmt8666_firmware
OR
mediatekmt8667_firmware
OR
mediatekmt8673_firmware
OR
mediatekmt8676_firmware
OR
mediatekmt8678_firmware
OR
mediatekmt8755_firmware
OR
mediatekmt8765_firmware
OR
mediatekmt8766_firmware
OR
mediatekmt8768_firmware
OR
mediatekmt8775_firmware
OR
mediatekmt8781_firmware
OR
mediatekmt8786_firmware
OR
mediatekmt8788_firmware
OR
mediatekmt8791t_firmware
OR
mediatekmt8792_firmware
OR
mediatekmt8796_firmware
OR
mediatekmt8893_firmware
VendorProductVersionCPE
googleandroid*cpe:2.3:o:google:android:*:*:*:*:*:*:*:*
mediatekmt2735_firmware*cpe:2.3:a:mediatek:mt2735_firmware:*:*:*:*:*:*:*:*
mediatekmt2737_firmware*cpe:2.3:a:mediatek:mt2737_firmware:*:*:*:*:*:*:*:*
mediatekmt6762_firmware*cpe:2.3:a:mediatek:mt6762_firmware:*:*:*:*:*:*:*:*
mediatekmt6765_firmware*cpe:2.3:a:mediatek:mt6765_firmware:*:*:*:*:*:*:*:*
mediatekmt6769_firmware*cpe:2.3:a:mediatek:mt6769_firmware:*:*:*:*:*:*:*:*
mediatekmt6833_firmware*cpe:2.3:a:mediatek:mt6833_firmware:*:*:*:*:*:*:*:*
mediatekmt6835_firmware*cpe:2.3:a:mediatek:mt6835_firmware:*:*:*:*:*:*:*:*
mediatekmt6853_firmware*cpe:2.3:a:mediatek:mt6853_firmware:*:*:*:*:*:*:*:*
mediatekmt6855_firmware*cpe:2.3:a:mediatek:mt6855_firmware:*:*:*:*:*:*:*:*
Rows per page:
1-10 of 481

CNA Affected

[
  {
    "vendor": "MediaTek, Inc.",
    "product": "MT2735, MT2737, MT6762, MT6765, MT6769, MT6833, MT6835, MT6853, MT6855, MT6873, MT6875, MT6877, MT6879, MT6883, MT6885, MT6889, MT6890, MT6891, MT6893, MT6895, MT6983, MT6985, MT6989, MT6990, MT8168, MT8173, MT8195, MT8321, MT8385, MT8390, MT8666, MT8667, MT8673, MT8676, MT8678, MT8755, MT8765, MT8766, MT8768, MT8775, MT8781, MT8786, MT8788, MT8791T, MT8792, MT8796, MT8893",
    "versions": [
      {
        "version": "Android 13.0, 14.0 / OpenWrt 19.07, 21.02 / Yocto 2.6, 3.3 / RDKB 2022Q3",
        "status": "affected"
      }
    ]
  }
]

CVSS3

6.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

6.9

Confidence

High

EPSS

0

Percentile

9.0%

Related for CVE-2024-20054