Reachable Assertion in MediaTek products - CVE-2024-20139
Published: December 3, 2024
Vulnerability identifier: #VU101146
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-20139
CWE-ID: CWE-617
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to perform service disruption.
The vulnerability exists due to improper handling of exceptional conditions within Bluetooth. A local application can perform service disruption.
Affected software
MT2737
MT3605
MT6985
MT6989
MT6990
MT7925
MT7927
MT8532
MT8678
MT8518S
MT3605
MT6985
MT6989
MT6990
MT7925
MT7927
MT8532
MT8678
MT8518S
How to mitigate CVE-2024-20139
Install security update from vendor's website.