First published: Mon Oct 07 2024(Updated: )
In wlan driver, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998892; Issue ID: MSV-1601.
Credit: security@mediatek.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
Google Android | =13.0 | |
Google Android | =14.0 | |
Any of | ||
Mediatek MT3605 | ||
MediaTek MT6985T | ||
MediaTek MT6989 | ||
MediaTek MT6990 | ||
MediaTek MT7927 | ||
MediaTek MT8678 | ||
MediaTek MT8796 | ||
MediaTek MT8893 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-20102 is critical as it involves a possible out of bounds read that can lead to remote information disclosure.
To fix CVE-2024-20102, you should apply the recommended patch ID ALPS08998892 as soon as possible.
CVE-2024-20102 affects Google Android versions 13.0 and 14.0.
No, CVE-2024-20102 does not require user interaction for exploitation.
CVE-2024-20102 is classified as an out of bounds read vulnerability due to improper input validation in the wlan driver.