Critical severity9.8NVD Advisory· Published Jul 1, 2024· Updated Jun 17, 2026
CVE-2024-20080
CVE-2024-20080
Description
In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08720039; Issue ID: MSV-1424.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:a:linuxfoundation:yocto:2.6:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:linuxfoundation:yocto:2.6:*:*:*:*:*:*:*
- cpe:2.3:a:linuxfoundation:yocto:3.3:*:*:*:*:*:*:*
- cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:rdkcentral:rdk-b:2022q3:*:*:*:*:*:*:*
- MediaTek, Inc./MT2735, MT2737, MT6761, MT6765, MT6768, MT6781, MT6785, MT6789, MT6833, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6879, MT6880, MT6883, MT6885, MT6886, MT6889, MT6890, MT6891, MT6893, MT6895, MT6980, MT6983, MT6985, MT6989, MT6990, MT8666, MT8667, MT8673, MT8676, MT8678v5Range: Android 13.0, 14.0 / Yocto 2.6, 3.3, 4.0 / RDK-B 22Q3
Patches
Vulnerability mechanics
References
1- corp.mediatek.com/product-security-bulletin/July-2024nvdVendor Advisory
News mentions
0No linked articles in our index yet.