CVE-2024-20152
MEDIUMDescription
In wlan STA driver, there is a possible reachable assertion due to improper exception handling. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00389047 / ALPS09136505; Issue ID: MSV-1798.
Is your site exposed to CVE-2024-20152?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| linuxfoundation | yocto |
| linuxfoundation | yocto |
| linuxfoundation | yocto |
| mediatek | software_development_kit |
| android | |
| android | |
| android | |
| openwrt | openwrt |
| mediatek | mt2737 |
| mediatek | mt3603 |
| mediatek | mt6835 |
| mediatek | mt6878 |
| mediatek | mt6886 |
| mediatek | mt6897 |
| mediatek | mt6990 |
| mediatek | mt7902 |
| mediatek | mt7920 |
| mediatek | mt7922 |
| mediatek | mt8518s |
| mediatek | mt8532 |
| mediatek | mt8755 |
| mediatek | mt8766 |
| mediatek | mt8768 |
| mediatek | mt8775 |
| mediatek | mt8781 |
| mediatek | mt8796 |
| mediatek | mt8798 |
| mediatek | mt8893 |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-20152? +
How severe is CVE-2024-20152? +
What products are affected by CVE-2024-20152? +
How do I check if I'm vulnerable to CVE-2024-20152? +
Related Vulnerabilities
An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a crafted transaction …
In a Bluetooth device, using RS9116-WiseConnect SDK experiences a Denial of Service, if it receives malformed L2CAP packets, only hard …
wb2osz/direwolf (Dire Wolf) versions up to and including 1.8, prior to commit 3658a87, contain a reachable assertion vulnerability in the …
A vulnerability has been found in some Dahua products could allow an unauthenticated remote attacker to send a specially crafted …
Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authenticated …
A vulnerability has been found in some Dahua products could allow an authenticated remote attacker to send a specially crafted …