Vulnerability

CVE-2024-20039

Component: CELLULAR
Location: FIRMWARE
In modem protocol, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01240012; Issue ID: MSV-1215.

Impact

Severity (Manufact.)

HIGH

Severity (NIST)

N/A

Severity (Android)

N/A

Chipsets

49

Devices

1015

Affected Hardware

NameAlso known asManufacturer
MT6739
MediaTek
MT6762
Helio P22
MediaTek
MT6765
Helio P35
MediaTek
MT6771
Helio P60
MediaTek
MT6768
Helio P65
MediaTek
MT6769T
Helio G80
MediaTek
MT6769Z
Helio G85
MediaTek
MT6781
Helio G96
MediaTek
MT6789
Helio G99
MediaTek
MT6833
Dimensity 6020
Dimensity 700
MediaTek
49 of 49 row(s) shown.

Rows per page

Page 1 of 5

Timeline

Introduced (est):
Jul 1, 2017
Reported:
Unknown
Advisory Published:
Apr 1, 2024
CVE Published:
Apr 1, 2024
Android Patch Level:
Apr 2024
For more information and a detailed analysis of the data presented on this website, please see our paper, to be presented at NDSS'25.
Follow us on Twitter