CVE-2024-20020: Medium severity android vulnerability
Published Mar 4, 2024
·Updated
In OPTEE, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08522504; Issue ID: ALPS08522504.
Affected Software
9 affected components
Google Android
All of the following
Google Android=13.0
Any of the following
MediaTek Mt2713
MediaTek Mt2715
MediaTek Mt8173
MediaTek Mt8188
MediaTek Mt8195
MediaTek Mt8390
MediaTek Mt8395
Event History
Mar 4, 2024
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityAffected Software
CVE Published
via MITRE·02:43 AM
Data Sourced
via MITRE·02:43 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-20020?
CVE-2024-20020 has a severity level that indicates it could lead to local information disclosure with system execution privileges required.
2
How do I fix CVE-2024-20020?
To fix CVE-2024-20020, apply the patch identified by ALPS08522504.
3
What type of vulnerability is CVE-2024-20020?
CVE-2024-20020 is an out of bounds write vulnerability caused by an incorrect bounds check.
4
Which systems are affected by CVE-2024-20020?
CVE-2024-20020 affects Google Android version 13.0 and possibly other systems using OPTEE.
5
Is user interaction required to exploit CVE-2024-20020?
No, user interaction is not needed for exploitation of CVE-2024-20020.