CVE-2024-20153

HIGH

Yocto - Remote Information Disclosure via Spoofed SSID

Title source: llm
STIX 2.1

Description

In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08990446 / ALPS09057442; Issue ID: MSV-1598.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0068
EPSS Percentile 71.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-304
Status published
Products (6)
google/android 14.0
google/android 15.0
linuxfoundation/yocto 3.3
linuxfoundation/yocto 4.0
linuxfoundation/yocto 5.0
mediatek/software_development_kit < 3.5
Published Jan 06, 2025
Tracked Since Feb 18, 2026