In wlan STA FW, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389045 / ALPS09136494; Issue ID: MSV-1796.
                
            Metrics
Affected Vendors & Products
References
        History
                    Tue, 22 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Google Google android Linuxfoundation Linuxfoundation yocto Mediatek Mediatek mt3603 Mediatek mt6835 Mediatek mt6878 Mediatek mt6886 Mediatek mt6897 Mediatek mt7902 Mediatek mt7920 Mediatek mt7922 Mediatek mt8518s Mediatek mt8532 Mediatek mt8766 Mediatek mt8768 Mediatek mt8775 Mediatek mt8796 Mediatek mt8798 Mediatek software Development Kit | |
| CPEs | cpe:2.3:a:linuxfoundation:yocto:3.3:*:*:*:*:*:*:* cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:* cpe:2.3:a:linuxfoundation:yocto:5.0:*:*:*:*:*:*:* cpe:2.3:a:mediatek:software_development_kit:*:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt3603:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6835:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6878:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6886:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6897:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7902:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7920:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7922:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8518s:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8532:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8766:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8768:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8775:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8796:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8798:-:*:*:*:*:*:*:* cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:* | |
| Vendors & Products | Google Google android Linuxfoundation Linuxfoundation yocto Mediatek Mediatek mt3603 Mediatek mt6835 Mediatek mt6878 Mediatek mt6886 Mediatek mt6897 Mediatek mt7902 Mediatek mt7920 Mediatek mt7922 Mediatek mt8518s Mediatek mt8532 Mediatek mt8766 Mediatek mt8768 Mediatek mt8775 Mediatek mt8796 Mediatek mt8798 Mediatek software Development Kit | 
Mon, 06 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | cvssV3_1 
 
 | 
Mon, 06 Jan 2025 03:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | In wlan STA FW, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389045 / ALPS09136494; Issue ID: MSV-1796. | |
| Weaknesses | CWE-787 | |
| References |  | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: MediaTek
Published: 2025-01-06T03:17:51.547Z
Updated: 2025-01-08T04:55:50.305Z
Reserved: 2023-11-02T13:35:35.186Z
Link: CVE-2024-20148
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-01-06T14:16:06.327Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-01-06T04:15:07.077
Modified: 2025-04-22T13:50:16.450
Link: CVE-2024-20148
 Redhat
                        Redhat
                    No data.