6.5
CVE-2024-20139
- EPSS 0.07%
- Veröffentlicht 02.12.2024 04:15:06
- Zuletzt bearbeitet 12.01.2026 16:29:10
- Quelle security@mediatek.com
- CVE-Watchlists
- Unerledigt
In Bluetooth firmware, there is a possible firmware asssert due to improper handling of exceptional conditions. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09001270; Issue ID: MSV-1600.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linuxfoundation ≫ Yocto Version3.3
Linuxfoundation ≫ Yocto Version4.0
Linuxfoundation ≫ Yocto Version5.0
Mediatek ≫ Software Development Kit Version <= 3.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.07% | 0.204 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-617 Reachable Assertion
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.