CVE-2024-20152

In wlan STA driver, there is a possible reachable assertion due to improper exception handling. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00389047 / ALPS09136505; Issue ID: MSV-1798.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.4 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
MediaTekCNA
---
---
CISA-ADPADP
4.4 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 1%
VendorProductVersion
linuxfoundationyocto
3.3
linuxfoundationyocto
4.0
linuxfoundationyocto
5.0
mediateksoftware_development_kit
𝑥
≤ 2.4
googleandroid
13.0
googleandroid
14.0
googleandroid
15.0
openwrtopenwrt
23.05
𝑥
= Vulnerable software versions