In modem, there is a possible selection of less-secure algorithm during the VoWiFi IKE due to a missing DH downgrade check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01286330; Issue ID: MSV-1430.
References
| Link | Resource |
|---|---|
| https://corp.mediatek.com/product-security-bulletin/June-2024 | Vendor Advisory |
| https://corp.mediatek.com/product-security-bulletin/June-2024 | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2024-06-03 02:15
Updated : 2025-04-25 18:38
NVD link : CVE-2024-20069
Mitre link : CVE-2024-20069
CVE.ORG link : CVE-2024-20069
JSON object : View
Products Affected
mediatek
- mt8771
- mt6889
- mt6853
- mt8797
- mt8675
- mt6883
- mt8791t
- mt6833
- mt6873
- nr15
- mt6855
- mt6875
- mt6877
- mt6885
- mt6893
- mt6875t
- mt6891
CWE
