CVE-2024-20004: Input Validation
In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of service, if NW sent invalid NR RRC Connection Setup message, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01191612; Issue ID: MOLY01195812 (MSV-985).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch MOLY01191612
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20004?
CVE-2024-20004 has been classified as a high severity vulnerability due to its potential to cause remote denial of service.
How do I fix CVE-2024-20004?
To fix CVE-2024-20004, apply the patch identified as MOLY01191612 as soon as possible.
What products are affected by CVE-2024-20004?
CVE-2024-20004 affects MediaTek NR15 based products that have improper input validation.
Can CVE-2024-20004 be exploited without user interaction?
Yes, CVE-2024-20004 can be exploited remotely without any user interaction required.
What causes CVE-2024-20004?
CVE-2024-20004 is caused by improper input validation that leads to a possible system crash.