VDB

CVE-2024-20152

CVE-2024-20152 PUBLISHED CVSS 6.900000095367432 MEDIUM

In wlan STA driver, there is a possible reachable assertion due to improper exception handling. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00389047 / ALPS09136505; Issue ID: MSV-1798.

EPSS 0.09% · 0.6th percentile

Risk Scores

CVSS 4.0
6.900000095367432
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.09%
0.6th percentile

Affected Products

VendorProductVersions
linuxfoundationyocto5.0, 4.0, 4.0
mediateksoftware_development_kit0, 0
googleandroid13.0, 15.0, 14.0
openwrtopenwrt23.05, 23.05
MediaTek, Inc.MT2737, MT3603, MT6835, MT6878, MT6886, MT6897, MT6990, MT7902, MT7920, MT7922, MT8518S, MT8532, MT8755, MT8766, MT8768, MT8775, MT8781, MT8796, MT8798, MT8893Android 13.0, 14.0, 15.0 / SDK release 2.4 and before / openWRT 23.05 / Yocto 3.3, 4.0, 5.0, Android 13.0, 14.0, 15.0 / SDK release 2.4 and before / openWRT 23.05 / Yocto 3.3, 4.0, 5.0

Timeline

  • Jan 6, 2025 EPSS Score
  • Jan 6, 2025 CVE Published
  • Jan 6, 2025 PoC Published
  • Jan 6, 2025 PoC Published
  • Jan 6, 2025 PoC Published
  • Jan 6, 2025 PoC Published
  • Jan 6, 2025 PoC Published
  • Jan 6, 2025 CVE Updated
  • Jan 22, 2025 EPSS Score
  • Feb 7, 2025 EPSS Score
  • Feb 8, 2025 Coalition ESS Score
  • Feb 23, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›