CVE-2024-20147
MEDIUMDescription
In Bluetooth FW, there is a possible reachable assertion due to improper exception handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389046 (Note: For MT79XX chipsets) / ALPS09136501 (Note: For MT2737, MT3603, MT6XXX, and MT8XXX chipsets); Issue ID: MSV-1797.
Is your site exposed to CVE-2024-20147?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| linuxfoundation | yocto |
| linuxfoundation | yocto |
| linuxfoundation | yocto |
| mediatek | software_development_kit |
| android | |
| android | |
| android | |
| openwrt | openwrt |
| mediatek | mt2737 |
| mediatek | mt3603 |
| mediatek | mt6835 |
| mediatek | mt6878 |
| mediatek | mt6886 |
| mediatek | mt6897 |
| mediatek | mt6985 |
| mediatek | mt6989 |
| mediatek | mt6990 |
| mediatek | mt7902 |
| mediatek | mt7920 |
| mediatek | mt7921 |
| mediatek | mt7922 |
| mediatek | mt7925 |
| mediatek | mt7927 |
| mediatek | mt8195 |
| mediatek | mt8370 |
| mediatek | mt8390 |
| mediatek | mt8395 |
| mediatek | mt8518s |
| mediatek | mt8532 |
| mediatek | mt8678 |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-20147? +
How severe is CVE-2024-20147? +
What products are affected by CVE-2024-20147? +
How do I check if I'm vulnerable to CVE-2024-20147? +
Related Vulnerabilities
An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a crafted transaction …
In a Bluetooth device, using RS9116-WiseConnect SDK experiences a Denial of Service, if it receives malformed L2CAP packets, only hard …
wb2osz/direwolf (Dire Wolf) versions up to and including 1.8, prior to commit 3658a87, contain a reachable assertion vulnerability in the …
A vulnerability has been found in some Dahua products could allow an unauthenticated remote attacker to send a specially crafted …
Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authenticated …
A vulnerability has been found in some Dahua products could allow an authenticated remote attacker to send a specially crafted …