CVE-2024-20069: Medium severity android vulnerability
In modem, there is a possible selection of less-secure algorithm during the VoWiFi IKE due to a missing DH downgrade check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01286330; Issue ID: MSV-1430.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20069?
The severity of CVE-2024-20069 is considered medium due to the potential for remote information disclosure.
How do I fix CVE-2024-20069?
To fix CVE-2024-20069, apply the patches provided in the latest security update for affected Android devices.
Which systems are affected by CVE-2024-20069?
CVE-2024-20069 affects Android devices that utilize VoWiFi with vulnerable modem configurations.
Is user interaction required to exploit CVE-2024-20069?
No, user interaction is not required for the exploitation of CVE-2024-20069.
What could be the potential impact of CVE-2024-20069?
The potential impact of CVE-2024-20069 is remote information disclosure, allowing unauthorized access to sensitive data.