Possible Out-of-Bounds Read Leads to Remote Denial of Service
CVE-2024-20129

7.5HIGH

Summary

This vulnerability in MediaTek's telephony software arises from a missing bounds check, potentially allowing unauthorized remote access that could lead to a denial of service. Notably, exploitation requires no user interaction, highlighting the severity of the issue. Affected users are urged to apply the patch ID ALPS09289881 to mitigate risks associated with this security flaw.

Affected Version(s)

MT6580, MT6739, MT6761, MT6765, MT6768, MT6779, MT6781, MT6785, MT6789, MT6833, MT6835, MT6853, MT6855, MT6873, MT6877, MT6878, MT6879, MT6883, MT6885, MT6886, MT6889, MT6893, MT6895, MT6896, MT6897, MT6983, MT6985, MT6989, MT8321, MT8666, MT8667, MT8673, MT8678, MT8765, MT8766, MT8766R, MT8768, MT8771, MT8781, MT8786, MT8788, MT8788E, MT8791T, MT8797, MT8798, MT8863T Android 13.0, 14.0, 15.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.