CVE-2024-20003: Input Validation
In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of service, if NW sent invalid NR RRC Connection Setup message, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01191612; Issue ID: MOLY01191612 (MSV-981).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch MOLY01191612
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20003?
CVE-2024-20003 is classified as a denial of service vulnerability that can lead to a system crash.
How do I fix CVE-2024-20003?
To fix CVE-2024-20003, apply the patch identified as MOLY01191612.
What causes CVE-2024-20003?
CVE-2024-20003 is caused by improper input validation in Modem NL1.
Who is affected by CVE-2024-20003?
CVE-2024-20003 affects devices running Google Android and specific MediaTek chipsets.
Is user interaction required to exploit CVE-2024-20003?
No, user interaction is not needed for the exploitation of CVE-2024-20003.