Vulnerability Details CVE-2024-20069
In modem, there is a possible selection of less-secure algorithm during the VoWiFi IKE due to a missing DH downgrade check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01286330; Issue ID: MSV-1430.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 40.6%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2024-20069
-
cpe:2.3:h:mediatek:mt6833:-
-
cpe:2.3:h:mediatek:mt6853:-
-
cpe:2.3:h:mediatek:mt6855:-
-
cpe:2.3:h:mediatek:mt6873:-
-
cpe:2.3:h:mediatek:mt6875:-
-
cpe:2.3:h:mediatek:mt6875t:-
-
cpe:2.3:h:mediatek:mt6877:-
-
cpe:2.3:h:mediatek:mt6883:-
-
cpe:2.3:h:mediatek:mt6885:-
-
cpe:2.3:h:mediatek:mt6889:-
-
cpe:2.3:h:mediatek:mt6891:-
-
cpe:2.3:h:mediatek:mt6893:-
-
cpe:2.3:h:mediatek:mt8675:-
-
cpe:2.3:h:mediatek:mt8771:-
-
cpe:2.3:h:mediatek:mt8791t:-
-
cpe:2.3:h:mediatek:mt8797:-
-
cpe:2.3:o:mediatek:nr15:-