CVE-2024-20153
HIGHDescription
In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08990446 / ALPS09057442; Issue ID: MSV-1598.
Is your site exposed to CVE-2024-20153?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| linuxfoundation | yocto |
| linuxfoundation | yocto |
| linuxfoundation | yocto |
| mediatek | software_development_kit |
| android | |
| android | |
| mediatek | mt2737 |
| mediatek | mt6989 |
| mediatek | mt6991 |
| mediatek | mt7925 |
| mediatek | mt8365 |
| mediatek | mt8518s |
| mediatek | mt8532 |
| mediatek | mt8666 |
| mediatek | mt8667 |
| mediatek | mt8673 |
| mediatek | mt8676 |
| mediatek | mt8678 |
| mediatek | mt8755 |
| mediatek | mt8766 |
| mediatek | mt8768 |
| mediatek | mt8775 |
| mediatek | mt8781 |
| mediatek | mt8786 |
| mediatek | mt8788 |
| mediatek | mt8796 |
| mediatek | mt8798 |
| mediatek | mt8893 |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-20153? +
How severe is CVE-2024-20153? +
What products are affected by CVE-2024-20153? +
How do I check if I'm vulnerable to CVE-2024-20153? +
Related Vulnerabilities
Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers …
The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to privilege escalation …
In composiohq/composio version 0.5.10, the API does not validate the `x-api-key` header's value during the authentication step. This vulnerability allows …
ChurchCRM is an open-source church management system. From 7.2.0 to 7.2.2, The fix for CVE-2026-4058 is incomplete. The hardening commit …
An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector …
Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) a Missing Critical Step in Authentication vulnerability. An unauthenticated attacker with remote …