Vulnerability Description
In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of service, if NW sent invalid NR RRC Connection Setup message, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01191612; Issue ID: MOLY01195812 (MSV-985).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mediatek | Nr15 | - |
| Mediatek | Mt2735 | - |
| Mediatek | Mt6297 | - |
| Mediatek | Mt6833 | - |
| Mediatek | Mt6853 | - |
| Mediatek | Mt6855 | - |
| Mediatek | Mt6873 | - |
| Mediatek | Mt6875 | - |
| Mediatek | Mt6875T | - |
| Mediatek | Mt6877 | - |
| Mediatek | Mt6880 | - |
| Mediatek | Mt6883 | - |
| Mediatek | Mt6885 | - |
| Mediatek | Mt6889 | - |
| Mediatek | Mt6890 | - |
| Mediatek | Mt6891 | - |
| Mediatek | Mt6893 | - |
| Mediatek | Mt8675 | - |
| Mediatek | Mt8791 | - |
| Mediatek | Mt8791T | - |
Related Weaknesses (CWE)
References
- https://corp.mediatek.com/product-security-bulletin/February-2024Vendor Advisory
- https://corp.mediatek.com/product-security-bulletin/February-2024Vendor Advisory
FAQ
What is CVE-2024-20004?
CVE-2024-20004 is a vulnerability with a CVSS score of 7.5 (HIGH). In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of service, if NW sent invalid NR RRC Connection Setup message, with no additional ...
How severe is CVE-2024-20004?
CVE-2024-20004 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-20004?
Check the references section above for vendor advisories and patch information. Affected products include: Mediatek Nr15, Mediatek Mt2735, Mediatek Mt6297, Mediatek Mt6833, Mediatek Mt6853.