CVE Vulnerabilities

CVE-2024-20153

Missing Critical Step in Authentication

Published: Jan 06, 2025 | Modified: Jan 12, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08990446 / ALPS09057442; Issue ID: MSV-1598.

Weakness

The product implements an authentication technique, but it skips a step that weakens the technique.

Affected Software

Name Vendor Start Version End Version
Yocto Linuxfoundation 3.3 (including) 3.3 (including)
Yocto Linuxfoundation 4.0 (including) 4.0 (including)
Yocto Linuxfoundation 5.0 (including) 5.0 (including)
Software_development_kit Mediatek * 3.5 (including)
Android Google 14.0 (including) 14.0 (including)
Android Google 15.0 (including) 15.0 (including)

References