CVE-2024-20147: Medium severity yocto project vulnerability
In Bluetooth FW, there is a possible reachable assertion due to improper exception handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389046 (Note: For MT79XX chipsets) / ALPS09136501 (Note: For MT2737, MT3603, MT6XXX, and MT8XXX chipsets); Issue ID: MSV-1797.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20147?
CVE-2024-20147 has a moderate severity as it allows for a remote denial of service without requiring user interaction.
How do I fix CVE-2024-20147?
To mitigate CVE-2024-20147, apply the relevant patches identified as WCNCR00389046 for MT79XX chipsets and ALPS09136501.
Which devices are affected by CVE-2024-20147?
CVE-2024-20147 affects software on various Yocto Project versions and Android 13.0, 14.0, and 15.0 among others.
Can CVE-2024-20147 be exploited remotely?
Yes, CVE-2024-20147 can be exploited remotely without any need for user interaction.
What type of vulnerability is CVE-2024-20147?
CVE-2024-20147 is a reachable assertion vulnerability caused by improper exception handling in Bluetooth firmware.