CVE-2024-20071: Input Validation
Published Jun 3, 2024
·Updated
In wlan driver, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00364733; Issue ID: MSV-1331.
Affected Software
7 affected components
All of the following
Any of the following
MediaTek Software Development Kit<=5.0.5.0
OpenWrt OpenWrt=19.07.0
OpenWrt OpenWrt=21.02.0
OpenWrt OpenWrt=23.05
Any of the following
MediaTek Mt6890
MediaTek Mt6990
MediaTek MT7622
Event History
Jun 3, 2024
CVE Published
via MITRE·02:04 AM
Data Sourced
via MITRE·02:04 AM
DescriptionWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-20071?
CVE-2024-20071 has a severity rating that indicates a potential local information disclosure vulnerability.
2
How do I fix CVE-2024-20071?
To fix CVE-2024-20071, apply the patch identified with ID WCNCR00364733 to the affected software.
3
What could be the impact of exploiting CVE-2024-20071?
Exploiting CVE-2024-20071 could lead to unauthorized local information disclosure.
4
Is user interaction required to exploit CVE-2024-20071?
No, user interaction is not required for the exploitation of CVE-2024-20071.
5
Which software versions are affected by CVE-2024-20071?
CVE-2024-20071 affects specific versions of the Mediatek Software Development Kit and OpenWrt releases.