ZeroHour

CVE-2024-20080

CVSS 3.1
9.8 critical
EPSS
<1%p21
Published
()
Modified
Description

In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08720039; Issue ID: MSV-1424.

Vendors
linuxfoundationrdkcentralgoogle
Products
yocto, rdk-b, android
Weakness
CWE-295
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.