CVE-2024-20145: Medium severity linuxfoundation Yocto vulnerability
In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09290940; Issue ID: MSV-2040.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20145?
CVE-2024-20145 is considered to have a high severity due to the potential for local escalation of privilege.
How do I fix CVE-2024-20145?
To fix CVE-2024-20145, users should apply the patch ID ALPS09290940 provided by the vendor.
What are the potential impacts of CVE-2024-20145?
The potential impact of CVE-2024-20145 includes unauthorized access and privilege escalation if an attacker has physical access to the affected device.
Is user interaction required for exploiting CVE-2024-20145?
Yes, user interaction is needed for exploiting CVE-2024-20145.
Which devices are affected by CVE-2024-20145?
CVE-2024-20145 affects devices running Google Android software.