CVE Vulnerabilities

CVE-2024-20080

Improper Certificate Validation

Published: Jul 01, 2024 | Modified: May 28, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08720039; Issue ID: MSV-1424.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
YoctoLinuxfoundation2.6 (including)2.6 (including)
YoctoLinuxfoundation3.3 (including)3.3 (including)
YoctoLinuxfoundation4.0 (including)4.0 (including)
Rdk-bRdkcentral2022q3 (including)2022q3 (including)
AndroidGoogle13.0 (including)13.0 (including)
AndroidGoogle14.0 (including)14.0 (including)

Potential Mitigations

References