CVE-2024-20069
MEDIUMDescription
In modem, there is a possible selection of less-secure algorithm during the VoWiFi IKE due to a missing DH downgrade check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01286330; Issue ID: MSV-1430.
Is your site exposed to CVE-2024-20069?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| mediatek | nr15 |
| mediatek | mt6833 |
| mediatek | mt6853 |
| mediatek | mt6855 |
| mediatek | mt6873 |
| mediatek | mt6875 |
| mediatek | mt6875t |
| mediatek | mt6877 |
| mediatek | mt6883 |
| mediatek | mt6885 |
| mediatek | mt6889 |
| mediatek | mt6891 |
| mediatek | mt6893 |
| mediatek | mt8675 |
| mediatek | mt8771 |
| mediatek | mt8791t |
| mediatek | mt8797 |
References
Frequently Asked Questions
What is CVE-2024-20069? +
How severe is CVE-2024-20069? +
What products are affected by CVE-2024-20069? +
How do I check if I'm vulnerable to CVE-2024-20069? +
Related Vulnerabilities
SIMPLE.ERP client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted …
SCRAM (Salted Challenge Response Authentication Mechanism) is part of the family of Simple Authentication and Security Layer (SASL, RFC 4422) …
When SmartStart Inclusion fails during the onboarding of a Z-Wave PIR sensor, the sensor will join the network as a …
The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the …
Wapro ERP Desktop is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an …
An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS …