Description

In modem, there is a possible selection of less-secure algorithm during the VoWiFi IKE due to a missing DH downgrade check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01286330; Issue ID: MSV-1430.

INFO

Published Date :

2024-06-03T02:04:48.667Z

Last Modified :

2024-08-01T21:52:31.659Z

Source :

MediaTek
AFFECTED PRODUCTS

The following products are affected by CVE-2024-20069 vulnerability.

Vendors Products
Mediatek
  • Mt6833
  • Mt6853
  • Mt6855
  • Mt6873
  • Mt6875
  • Mt6875t
  • Mt6877
  • Mt6883
  • Mt6885
  • Mt6889
  • Mt6891
  • Mt6893
  • Mt8675
  • Mt8771
  • Mt8791t
  • Mt8797
  • Nr15
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-20069.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact