CVE-2024-20139

EUVD-2024-17854
In Bluetooth firmware, there is a possible firmware asssert due to improper handling of exceptional conditions. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09001270; Issue ID: MSV-1600.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 20%
Affected Products (NVD)
VendorProductVersion
linuxfoundationyocto
3.3
linuxfoundationyocto
4.0
linuxfoundationyocto
5.0
mediateksoftware_development_kit
𝑥
≤ 3.3
googleandroid
13.0
googleandroid
14.0
googleandroid
15.0
openwrtopenwrt
23.05.0
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
mediatekmt2737
𝑥
≤ *
ADP
mediatekmt3605
𝑥
≤ *
ADP
mediatekmt6985
𝑥
≤ *
ADP
mediatekmt6989
𝑥
≤ *
ADP
mediatekmt6990
𝑥
≤ *
ADP
mediatekmt7925
𝑥
≤ *
ADP
mediatekmt7927
𝑥
≤ *
ADP
mediatekmt8518s
𝑥
≤ *
ADP
mediatekmt8532
𝑥
≤ *
ADP
mediatekmt8678
𝑥
≤ *
ADP