Out-of-bounds read in MediaTek products - CVE-2024-20138
Published: December 3, 2024
Vulnerability identifier: #VU101145
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-20138
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improper input validation within wlan. A local application can gain access to sensitive information.
Affected software
MT3605
MT6985
MT6989
MT6990
MT7925
MT7927
MT8195
MT8370
MT8390
MT6985
MT6989
MT6990
MT7925
MT7927
MT8195
MT8370
MT8390
How to mitigate CVE-2024-20138
Install security update from vendor's website.