VDB

CVE-2024-20055

CVE-2024-20055 PUBLISHED CVSS 6.300000190734863 MEDIUM

In imgsys, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation Patch ID: ALPS08518692; Issue ID: MSV-1012.

EPSS 0.08% · 0.2th percentile

Risk Scores

CVSS 3.1
6.300000190734863
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS Score
0.08%
0.2th percentile

Affected Products

VendorProductVersions
mediatekiot_yocto23.2
linuxfoundationyocto4.0
MediaTek, Inc.MT2713, MT8168, MT8173, MT8175, MT8188, MT8195, MT8365, MT8370, MT8390, MT8395, MT8673, MT8696, MT8781, MT8795T, MT8798, MT8871Android 12.0, 13.0 / Yocto 4.0 / IOT-v23.2
googleandroid12.0, 13.0

Timeline

  • Apr 1, 2024 EPSS Score
  • Apr 1, 2024 CVE Published
  • Apr 26, 2024 EPSS Score
  • May 22, 2024 EPSS Score
  • Jun 17, 2024 EPSS Score
  • Jul 13, 2024 EPSS Score
  • Aug 7, 2024 EPSS Score
  • Sep 2, 2024 EPSS Score
  • Sep 27, 2024 EPSS Score
  • Oct 4, 2024 Coalition ESS Score
  • Oct 23, 2024 EPSS Score
  • Nov 17, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›