CVE-2024-20066

HIGH

MediaTek NR16 and NR17 - Remote Denial of Service via Out-of-Bounds Write

Title source: llm
STIX 2.1

Description

In modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is no needed for exploitation. Patch ID: MOLY01267281; Issue ID: MSV-1477.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0310
EPSS Percentile 87.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-787
Status published
Products (2)
mediatek/nr16
mediatek/nr17
Published Jun 03, 2024
Tracked Since Feb 18, 2026