CVE-2024-20068

MEDIUM

MediaTek NR16 and NR17 - Remote Denial of Service via Improper Input Validation

Title source: llm
STIX 2.1

Description

In modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is no needed for exploitation. Patch ID: MOLY01270721; Issue ID: MSV-1479.

References (1)

Core 1

Scores

CVSS v3 5.9
EPSS 0.0231
EPSS Percentile 85.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-787
Status published
Products (2)
mediatek/nr16
mediatek/nr17
Published Jun 03, 2024
Tracked Since Feb 18, 2026