CVE-2024-20136: Medium severity rdk central rdkb vulnerability
In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09121847; Issue ID: MSV-1821.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20136?
The severity of CVE-2024-20136 is classified as local information disclosure due to an out of bounds read.
How do I fix CVE-2024-20136?
To fix CVE-2024-20136, apply the patch identified as ALPS09121847.
Which software versions are affected by CVE-2024-20136?
CVE-2024-20136 affects RDK Central RDKB versions 2022q3 and 2024q1, as well as various versions of Android and OpenWRT.
Is user interaction required to exploit CVE-2024-20136?
No, user interaction is not needed for exploitation of CVE-2024-20136.
What can be the potential impact of CVE-2024-20136?
The potential impact of CVE-2024-20136 includes unauthorized access to sensitive local information without requiring additional execution privileges.