CVE-2024-20080

Published Jul 1, 2024

Last updated a year ago

Overview

Description
In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08720039; Issue ID: MSV-1424.
Source
security@mediatek.com
NVD status
Analyzed
Products
yocto, rdk-b, android

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security@mediatek.com
CWE-295
nvd@nist.gov
CWE-295

Social media

Hype score
Not currently trending

Configurations