CVE-2024-20149: Input Validation
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01231341 / MOLY01263331 / MOLY01233835; Issue ID: MSV-2165.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20149?
CVE-2024-20149 has a severity rating that indicates a potential remote denial of service due to improper input validation.
How do I fix CVE-2024-20149?
To fix CVE-2024-20149, apply the appropriate patches identified by Patch IDs: MOLY01231341, MOLY01263331, or MOLY01233835.
What are the affected systems for CVE-2024-20149?
CVE-2024-20149 affects various MediaTek modem versions, including LR12, LR13, NR15, NR16, and NR17 series.
Is user interaction required to exploit CVE-2024-20149?
No, user interaction is not required to exploit CVE-2024-20149, making it easier to execute remotely.
What could be the impact of CVE-2024-20149?
The impact of CVE-2024-20149 could result in a system crash leading to a remote denial of service.