CVE Vulnerabilities

CVE-2024-20080

Improper Certificate Validation

Published: Jul 01, 2024 | Modified: May 28, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08720039; Issue ID: MSV-1424.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Yocto Linuxfoundation 2.6 (including) 2.6 (including)
Yocto Linuxfoundation 3.3 (including) 3.3 (including)
Yocto Linuxfoundation 4.0 (including) 4.0 (including)
Rdk-b Rdkcentral 2022q3 (including) 2022q3 (including)
Android Google 13.0 (including) 13.0 (including)
Android Google 14.0 (including) 14.0 (including)

Potential Mitigations

References