Vulnerability

CVE-2024-20004

Component: CELLULAR
Location: FIRMWARE
In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of service, if NW sent invalid NR RRC Connection Setup message, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01191612; Issue ID: MOLY01195812 (MSV-985).

Impact

Severity (Manufact.)

MEDIUM

Severity (NIST)

7.5

Severity (Android)

N/A

Chipsets

38

Devices

358

Affected Hardware

NameAlso known asManufacturer
MT6833
Dimensity 6020
Dimensity 700
MediaTek
MT6833V/ZA
Dimensity 6020
Dimensity 700
MediaTek
MT6833V/NZA
Dimensity 700
MediaTek
MT6853V/ZA
Dimensity 720
MediaTek
MT6853V/NZA
Dimensity 720
MediaTek
MT6853V/TNZA
Dimensity 800U
MediaTek
MT6853T
Dimensity 800U
MediaTek
MT6873
Dimensity 800
MediaTek
MT6833
Dimensity 6080
Dimensity 810
MediaTek
MT6833V/PNZA
Dimensity 810
MediaTek
38 of 38 row(s) shown.

Rows per page

Page 1 of 4

Timeline

Introduced (est):
Jan 1, 2020
Reported:
Unknown
Advisory Published:
Feb 5, 2024
CVE Published:
Feb 5, 2024
Android Patch Level:
None
For more information and a detailed analysis of the data presented on this website, please see our paper, to be presented at NDSS'25.
Follow us on Twitter