CVE-2024-20023

EUVD-2024-17738
In flashc, there is a possible out of bounds write due to lack of valudation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541638; Issue ID: ALPS08541638.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 3%
Affected Products (NVD)
VendorProductVersion
linuxfoundationyocto
3.3
googleandroid
12.0
googleandroid
13.0
googleandroid
14.0
openwrtopenwrt
19.07.0
openwrtopenwrt
21.02.0
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
mediatekmt2713
𝑥
≤ *
ADP
mediatekmt2737
𝑥
≤ *
ADP
mediatekmt6781
𝑥
≤ *
ADP
mediatekmt6789
𝑥
≤ *
ADP
mediatekmt6835
𝑥
≤ *
ADP
mediatekmt6855
𝑥
≤ *
ADP
mediatekmt6879
𝑥
≤ *
ADP
mediatekmt6880
𝑥
≤ *
ADP
mediatekmt6886
𝑥
≤ *
ADP
mediatekmt6890
𝑥
≤ *
ADP
mediatekmt6895
𝑥
≤ *
ADP
mediatekmt6980
𝑥
≤ *
ADP
mediatekmt6983
𝑥
≤ *
ADP
mediatekmt6985
𝑥
≤ *
ADP
mediatekmt6989
𝑥
≤ *
ADP
mediatekmt6990
𝑥
≤ *
ADP
mediatekmt8188
𝑥
≤ *
ADP
mediatekmt8188t
𝑥
≤ *
ADP
mediatekmt8370
𝑥
≤ *
ADP
mediatekmt8390
𝑥
≤ *
ADP
mediatekmt8673
𝑥
≤ *
ADP
mediatekmt8676
𝑥
≤ *
ADP
mediatekmt8678
𝑥
≤ *
ADP