VDB

CVE-2024-20080

CVE-2024-20080 PUBLISHED CVSS 9.800000190734863 CRITICAL

In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08720039; Issue ID: MSV-1424.

EPSS 0.29% · 21.3th percentile

Risk Scores

CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.29%
21.3th percentile

Affected Products

VendorProductVersions
mediatekmt2737-, -
mediatekmt6883-, -
mediatekmt6886-, -
mediatekmt6891-, -
mediatekmt8667-, -
rdkcentralrdk-b*, 2022q3
mediatekmt6990-, -
mediatekmt6983-, *
mediatekmt6785-, -
googleandroid13.0, 14.0, 14.0
mediatekmt6853-, -
mediatekmt6833-, -
mediatekmt6889*, -
mediatekmt6875-, -
mediatekmt6980-, -
mediatekmt2735*, -
mediatekmt6893-, -
mediatekmt6855*, -
mediatekmt6885-, -
mediatekmt6768-, -

…and 20 more

Timeline

  • Jul 1, 2024 EPSS Score
  • Jul 1, 2024 CVE Published
  • Aug 15, 2024 EPSS Score
  • Sep 7, 2024 EPSS Score
  • Oct 4, 2024 Coalition ESS Score
  • Oct 22, 2024 EPSS Score
  • Dec 7, 2024 EPSS Score
  • Jan 21, 2025 EPSS Score
  • Feb 13, 2025 EPSS Score
  • Mar 17, 2025 EPSS Score
  • Apr 22, 2025 EPSS Score
  • Jun 1, 2025 Coalition ESS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›