CVE-2024-20019

In wlan driver, there is a possible memory leak due to improper input handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00351241; Issue ID: MSV-1173.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:mediatek:software_package:*:*:*:*:*:*:*:*
OR cpe:2.3:h:mediatek:mt7925:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7927:-:*:*:*:*:*:*:*

History

05 May 2025, 17:54

Type Values Removed Values Added
CPE cpe:2.3:h:mediatek:mt7927:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7925:-:*:*:*:*:*:*:*
cpe:2.3:a:mediatek:software_package:*:*:*:*:*:*:*:*
References () https://corp.mediatek.com/product-security-bulletin/March-2024 - () https://corp.mediatek.com/product-security-bulletin/March-2024 - Vendor Advisory
First Time Mediatek mt7927
Mediatek software Package
Mediatek mt7925
Mediatek

21 Nov 2024, 08:51

Type Values Removed Values Added
References () https://corp.mediatek.com/product-security-bulletin/March-2024 - () https://corp.mediatek.com/product-security-bulletin/March-2024 -

01 Aug 2024, 13:46

Type Values Removed Values Added
CWE CWE-200
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.9

04 Mar 2024, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-04 03:15

Updated : 2025-05-05 17:54


NVD link : CVE-2024-20019

Mitre link : CVE-2024-20019

CVE.ORG link : CVE-2024-20019


JSON object : View

Products Affected

mediatek

  • software_package
  • mt7927
  • mt7925
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor