CVE-2024-20153
HIGHDescription
In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08990446 / ALPS09057442; Issue ID: MSV-1598.
Is your site exposed to CVE-2024-20153?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| linuxfoundation | yocto |
| linuxfoundation | yocto |
| linuxfoundation | yocto |
| mediatek | software_development_kit |
| android | |
| android | |
| mediatek | mt2737 |
| mediatek | mt6989 |
| mediatek | mt6991 |
| mediatek | mt7925 |
| mediatek | mt8365 |
| mediatek | mt8518s |
| mediatek | mt8532 |
| mediatek | mt8666 |
| mediatek | mt8667 |
| mediatek | mt8673 |
| mediatek | mt8676 |
| mediatek | mt8678 |
| mediatek | mt8755 |
| mediatek | mt8766 |
| mediatek | mt8768 |
| mediatek | mt8775 |
| mediatek | mt8781 |
| mediatek | mt8786 |
| mediatek | mt8788 |
| mediatek | mt8796 |
| mediatek | mt8798 |
| mediatek | mt8893 |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-20153? +
How severe is CVE-2024-20153? +
What products are affected by CVE-2024-20153? +
How do I check if I'm vulnerable to CVE-2024-20153? +
Related Vulnerabilities
The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to privilege escalation …
In composiohq/composio version 0.5.10, the API does not validate the `x-api-key` header's value during the authentication step. This vulnerability allows …
ChurchCRM is an open-source church management system. From 7.2.0 to 7.2.2, The fix for CVE-2026-4058 is incomplete. The hardening commit …
Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) a Missing Critical Step in Authentication vulnerability. An unauthenticated attacker with remote …
An IDOR (Insecure Direct Object Reference) vulnerability exists in transformeroptimus/superagi version v0.0.14. The application fails to properly check authorization for …
An authentication bypass vulnerability exists in gaizhenbiao/ChuanhuChatGPT, as of commit 3856d4f, allowing any user to read and delete other users' …