7.5
CVE-2024-20003
- EPSS 1.4%
- Published 05.02.2024 06:15:47
- Last modified 21.11.2024 08:51:46
- Source security@mediatek.com
- Teams watchlist Login
- Open Login
In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of service, if NW sent invalid NR RRC Connection Setup message, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01191612; Issue ID: MOLY01191612 (MSV-981).
Data is provided by the National Vulnerability Database (NVD)
Mediatek ≫ Nr15 Version-
Mediatek ≫ Mt2735 Version-
Mediatek ≫ Mt6297 Version-
Mediatek ≫ Mt6833 Version-
Mediatek ≫ Mt6853 Version-
Mediatek ≫ Mt6855 Version-
Mediatek ≫ Mt6873 Version-
Mediatek ≫ Mt6875 Version-
Mediatek ≫ Mt6875t Version-
Mediatek ≫ Mt6877 Version-
Mediatek ≫ Mt6880 Version-
Mediatek ≫ Mt6883 Version-
Mediatek ≫ Mt6885 Version-
Mediatek ≫ Mt6889 Version-
Mediatek ≫ Mt6890 Version-
Mediatek ≫ Mt6891 Version-
Mediatek ≫ Mt6893 Version-
Mediatek ≫ Mt8675 Version-
Mediatek ≫ Mt8791 Version-
Mediatek ≫ Mt8791t Version-
Mediatek ≫ Mt8797 Version-
Mediatek ≫ Mt6297 Version-
Mediatek ≫ Mt6833 Version-
Mediatek ≫ Mt6853 Version-
Mediatek ≫ Mt6855 Version-
Mediatek ≫ Mt6873 Version-
Mediatek ≫ Mt6875 Version-
Mediatek ≫ Mt6875t Version-
Mediatek ≫ Mt6877 Version-
Mediatek ≫ Mt6880 Version-
Mediatek ≫ Mt6883 Version-
Mediatek ≫ Mt6885 Version-
Mediatek ≫ Mt6889 Version-
Mediatek ≫ Mt6890 Version-
Mediatek ≫ Mt6891 Version-
Mediatek ≫ Mt6893 Version-
Mediatek ≫ Mt8675 Version-
Mediatek ≫ Mt8791 Version-
Mediatek ≫ Mt8791t Version-
Mediatek ≫ Mt8797 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 1.4% | 0.798 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.