CVE-2024-20139

MEDIUM

Bluetooth Firmware - DoS

Title source: llm
STIX 2.1

Description

In Bluetooth firmware, there is a possible firmware asssert due to improper handling of exceptional conditions. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09001270; Issue ID: MSV-1600.

Scores

CVSS v3 6.5
EPSS 0.0006
EPSS Percentile 20.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-617
Status published
Products (8)
google/android 13.0
google/android 14.0
google/android 15.0
linuxfoundation/yocto 3.3
linuxfoundation/yocto 4.0
linuxfoundation/yocto 5.0
mediatek/software_development_kit < 3.3
openwrt/openwrt 23.05.0
Published Dec 02, 2024
Tracked Since Feb 18, 2026