CVE-2024-20148
critical · 9.8In wlan STA FW, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389045 / ALPS09136494; Issue ID: MSV-1796.
9.8
CVSS
0.3%
EPSS (exploit prob.)
18th
EPSS percentile
2025-01-06
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-787
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| linuxfoundation | yocto | 3.3 |
| linuxfoundation | yocto | 4.0 |
| linuxfoundation | yocto | 5.0 |
| mediatek | software_development_kit | <= 2.4 |
| android | 13.0 | |
| android | 14.0 | |
| android | 15.0 | |
| mediatek | mt3603 | all versions |
| mediatek | mt6835 | all versions |
| mediatek | mt6878 | all versions |
| mediatek | mt6886 | all versions |
| mediatek | mt6897 | all versions |
| mediatek | mt7902 | all versions |
| mediatek | mt7920 | all versions |
| mediatek | mt7922 | all versions |
| mediatek | mt8518s | all versions |
| mediatek | mt8532 | all versions |
| mediatek | mt8766 | all versions |
| mediatek | mt8768 | all versions |
| mediatek | mt8775 | all versions |
| mediatek | mt8796 | all versions |
| mediatek | mt8798 | all versions |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2024-20148