// For flags

CVE-2024-20069

 

Severity Score

6.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track
*SSVC
Descriptions

In modem, there is a possible selection of less-secure algorithm during the VoWiFi IKE due to a missing DH downgrade check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01286330; Issue ID: MSV-1430.

En el módem, existe una posible selección de algoritmos menos seguros durante el IKE de VoWiFi debido a que falta una verificación de degradación de DH. Esto podría conducir a la divulgación remota de información sin necesidad de privilegios de ejecución adicionales. Se necesita la interacción del usuario para la explotación. ID de parche: MOLY01286330; ID del problema: MSV-1430.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:Track
Exploitation
None
Automatable
No
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2023-11-02 CVE Reserved
  • 2024-06-03 CVE Published
  • 2024-06-03 EPSS Updated
  • 2024-08-01 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-757: Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Mediatek
Search vendor "Mediatek"
Mt6833
Search vendor "Mediatek" for product "Mt6833"
*-
Affected
Mediatek
Search vendor "Mediatek"
Mt6853
Search vendor "Mediatek" for product "Mt6853"
*-
Affected
Mediatek
Search vendor "Mediatek"
Mt6855
Search vendor "Mediatek" for product "Mt6855"
*-
Affected
Mediatek
Search vendor "Mediatek"
Mt6873
Search vendor "Mediatek" for product "Mt6873"
*-
Affected
Mediatek
Search vendor "Mediatek"
Mt6875
Search vendor "Mediatek" for product "Mt6875"
*-
Affected
Mediatek
Search vendor "Mediatek"
Mt6875t
Search vendor "Mediatek" for product "Mt6875t"
*-
Affected
Mediatek
Search vendor "Mediatek"
Mt6877
Search vendor "Mediatek" for product "Mt6877"
*-
Affected
Mediatek
Search vendor "Mediatek"
Mt6883
Search vendor "Mediatek" for product "Mt6883"
*-
Affected
Mediatek
Search vendor "Mediatek"
Mt6885
Search vendor "Mediatek" for product "Mt6885"
*-
Affected
Mediatek
Search vendor "Mediatek"
Mt6889
Search vendor "Mediatek" for product "Mt6889"
*-
Affected
Mediatek
Search vendor "Mediatek"
Mt6891
Search vendor "Mediatek" for product "Mt6891"
*-
Affected
Mediatek
Search vendor "Mediatek"
Mt6893
Search vendor "Mediatek" for product "Mt6893"
*-
Affected
Mediatek
Search vendor "Mediatek"
Mt8675
Search vendor "Mediatek" for product "Mt8675"
*-
Affected
Mediatek
Search vendor "Mediatek"
Mt8771
Search vendor "Mediatek" for product "Mt8771"
*-
Affected
Mediatek
Search vendor "Mediatek"
Mt8791t
Search vendor "Mediatek" for product "Mt8791t"
*-
Affected
Mediatek
Search vendor "Mediatek"
Mt8797
Search vendor "Mediatek" for product "Mt8797"
*-
Affected