Possible Escalation of Privilege Due to Improper Certificate Validation
CVE-2024-20080

Currently unrated

Summary

In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08720039; Issue ID: MSV-1424.

Affected Version(s)

MT2735, MT2737, MT6761, MT6765, MT6768, MT6781, MT6785, MT6789, MT6833, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6879, MT6880, MT6883, MT6885, MT6886, MT6889, MT6890, MT6891, MT6893, MT6895, MT6980, MT6983, MT6985, MT6989, MT6990, MT8666, MT8667, MT8673, MT8676, MT8678 Android 13.0, 14.0 / Yocto 2.6, 3.3, 4.0 / RDK-B 22Q3

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.