CVE-2024-20154: High severity Google Android vulnerability
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00720348; Issue ID: MSV-2392.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20154?
CVE-2024-20154 is considered a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2024-20154?
To mitigate CVE-2024-20154, ensure that you apply the latest security updates provided by your device manufacturer.
Who is affected by CVE-2024-20154?
CVE-2024-20154 primarily affects devices running Google Android that utilize affected MediaTek chipsets.
Can CVE-2024-20154 be exploited without user interaction?
Yes, CVE-2024-20154 can be exploited remotely without any user interaction required.
What type of attack does CVE-2024-20154 enable?
CVE-2024-20154 enables potential remote code execution through an out of bounds write vulnerability.