First published: Mon Jun 03 2024(Updated: )
In modem, there is a possible information disclosure due to using risky cryptographic algorithm during connection establishment negotiation. This could lead to remote information disclosure, when weak encryption algorithm is used, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00942482; Issue ID: MSV-1469.
Credit: security@mediatek.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
MediaTek NR15 | ||
MediaTek NR16 | ||
MediaTek NR17 | ||
Any of | ||
MediaTek MT6298 | ||
MediaTek MT6813 | ||
MediaTek MT6815 | ||
MediaTek MT6833 | ||
MediaTek MT6835 | ||
MediaTek MT6853 | ||
MediaTek MT6855 | ||
MediaTek MT6873 | ||
MediaTek MT6875T | ||
MediaTek MT6875T | ||
MediaTek MT6877 | ||
MediaTek MT6878 | ||
MediaTek MT6879 | ||
MediaTek MT6883 | ||
MediaTek MT6885 | ||
MediaTek MT6889 | ||
MediaTek MT6891 | ||
MediaTek MT6893 | ||
MediaTek MT6895 | ||
MediaTek MT6895T | ||
MediaTek MT6896 | ||
MediaTek MT6897 | ||
MediaTek MT6980D | ||
MediaTek MT6980D | ||
MediaTek MT6983 | ||
MediaTek MT6990 | ||
MediaTek MT8673 | ||
MediaTek MT8675 | ||
MediaTek MT8765 | ||
MediaTek MT8766Z | ||
MediaTek MT8768 | ||
MediaTek MT8771 | ||
MediaTek MT8786 | ||
MediaTek MT8791T | ||
MediaTek MT8792 | ||
MediaTek MT8797 WiFi | ||
MediaTek MT8798 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-20070 is marked as high due to the potential for remote information disclosure.
To fix CVE-2024-20070, it is recommended to update the affected MediaTek devices to the latest firmware versions that address the vulnerability.
CVE-2024-20070 affects various MediaTek modem systems, including NR15, NR16, and NR17.
Attackers can exploit CVE-2024-20070 to gain unauthorized access to sensitive information due to the use of a risky cryptographic algorithm.
No, user interaction is not required to exploit CVE-2024-20070 as the attack can occur remotely.