CVE-2024-20065: Medium severity android vulnerability
In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08698617; Issue ID: MSV-1394.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20065?
CVE-2024-20065 is classified as a moderate severity vulnerability due to the possibility of local information disclosure.
How do I fix CVE-2024-20065?
To fix CVE-2024-20065, ensure that your Android device is updated with the latest security patches provided by your vendor.
Who is affected by CVE-2024-20065?
CVE-2024-20065 affects devices running certain versions of Android that do not have the necessary permission checks in their telephony feature.
Is user interaction required to exploit CVE-2024-20065?
No, user interaction is not needed for the exploitation of CVE-2024-20065, making it easier for potential attackers.
What type of information can be disclosed due to CVE-2024-20065?
CVE-2024-20065 may lead to the disclosure of local information related to the telephony features of affected Android devices.