VDB
CVE-2024-20055
CVE-2024-20055
PUBLISHED
CVSS 6.300000190734863 MEDIUM
In imgsys, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation Patch ID: ALPS08518692; Issue ID: MSV-1012.
EPSS 0.08% · 0.2th percentile
Risk Scores
CVSS 3.1
6.300000190734863
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS Score
0.08%
0.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| mediatek | iot_yocto | 23.2 |
| linuxfoundation | yocto | 4.0 |
| MediaTek, Inc. | MT2713, MT8168, MT8173, MT8175, MT8188, MT8195, MT8365, MT8370, MT8390, MT8395, MT8673, MT8696, MT8781, MT8795T, MT8798, MT8871 | Android 12.0, 13.0 / Yocto 4.0 / IOT-v23.2 |
| android | 12.0, 13.0 |
Timeline
- Apr 1, 2024 EPSS Score
- Apr 1, 2024 CVE Published
- Apr 26, 2024 EPSS Score
- May 22, 2024 EPSS Score
- Jun 17, 2024 EPSS Score
- Jul 13, 2024 EPSS Score
- Aug 7, 2024 EPSS Score
- Sep 2, 2024 EPSS Score
- Sep 27, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 23, 2024 EPSS Score
- Nov 17, 2024 EPSS Score