CVE-2024-20070: Weak Encryption
In modem, there is a possible information disclosure due to using risky cryptographic algorithm during connection establishment negotiation. This could lead to remote information disclosure, when weak encryption algorithm is used, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00942482; Issue ID: MSV-1469.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20070?
The severity of CVE-2024-20070 is marked as high due to the potential for remote information disclosure.
How do I fix CVE-2024-20070?
To fix CVE-2024-20070, it is recommended to update the affected MediaTek devices to the latest firmware versions that address the vulnerability.
What type of systems are affected by CVE-2024-20070?
CVE-2024-20070 affects various MediaTek modem systems, including NR15, NR16, and NR17.
What can attackers achieve with CVE-2024-20070?
Attackers can exploit CVE-2024-20070 to gain unauthorized access to sensitive information due to the use of a risky cryptographic algorithm.
Is user interaction required to exploit CVE-2024-20070?
No, user interaction is not required to exploit CVE-2024-20070 as the attack can occur remotely.