In OPTEE, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08522504; Issue ID: ALPS08522504.
History

Thu, 30 Jan 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Mediatek
Mediatek mt2713
Mediatek mt2715
Mediatek mt8173
Mediatek mt8188
Mediatek mt8195
Mediatek mt8390
Mediatek mt8395
Weaknesses CWE-787
CPEs cpe:2.3:h:mediatek:mt2713:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt2715:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8173:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8188:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8195:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8390:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8395:-:*:*:*:*:*:*:*
cpe:2.3:o:google:android:13.0:-:*:*:*:*:*:*
Vendors & Products Google
Google android
Mediatek
Mediatek mt2713
Mediatek mt2715
Mediatek mt8173
Mediatek mt8188
Mediatek mt8195
Mediatek mt8390
Mediatek mt8395
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published:

Updated: 2024-08-01T21:52:31.578Z

Reserved: 2023-11-02T13:35:35.151Z

Link: CVE-2024-20020

cve-icon Vulnrichment

Updated: 2024-08-01T21:52:31.578Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-04T03:15:07.107

Modified: 2025-01-30T15:07:55.143

Link: CVE-2024-20020

cve-icon Redhat

No data.