« Volver al listado

CVE-2024-20137

Estado: AplazadaAlta (7.5)—

In wlan driver, there is a possible client disconnection due to improper handling of exceptional conditions. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00384543; Issue ID: MSV-1727.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vector CVSS N/N/L/N sin UI indica acceso remoto sin privilegios ni interacción. El CWE-248 (improper handling of exceptions) en driver WLAN causa desconexión remota masiva (DoS de disponibilidad). T1499.004 (Flooding) por disrupción del servicio.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-20137",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-20137",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-12-02T15:48:07.775098Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@mediatek.com",
      "affectedData": [
        {
          "vendor": "MediaTek, Inc.",
          "product": "MT6890, MT7622, MT7915, MT7916, MT7981, MT7986",
          "versions": [
            {
              "status": "affected",
              "version": "SDK release 7.4.0.1 (MT7915) and 7.6.7.2 (MT7916, MT798X) and before"
            }
          ]
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:h:mediatek:mt6890:-:*:*:*:*:*:*:*"
          ],
          "vendor": "mediatek",
          "product": "mt6890",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "*"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:h:mediatek:mt7622:-:*:*:*:*:*:*:*"
          ],
          "vendor": "mediatek",
          "product": "mt7622",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "*"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:h:mediatek:mt7915:-:*:*:*:*:*:*:*"
          ],
          "vendor": "mediatek",
          "product": "mt7915",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "*"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:h:mediatek:mt7916:-:*:*:*:*:*:*:*"
          ],
          "vendor": "mediatek",
          "product": "mt7916",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "*"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:h:mediatek:mt7981:-:*:*:*:*:*:*:*"
          ],
          "vendor": "mediatek",
          "product": "mt7981",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "*"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:h:mediatek:mt7986:-:*:*:*:*:*:*:*"
          ],
          "vendor": "mediatek",
          "product": "mt7986",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "*"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-12-02T04:15:06.030",
  "references": [
    {
      "url": "https://corp.mediatek.com/product-security-bulletin/December-2024",
      "source": "security@mediatek.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@mediatek.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-248"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In wlan driver, there is a possible client disconnection due to improper handling of exceptional conditions. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00384543; Issue ID: MSV-1727."
    },
    {
      "lang": "es",
      "value": "En el controlador WLAN, existe una posible desconexión del cliente debido a la gestión inadecuada de condiciones excepcionales. Esto podría provocar una denegación de servicio remota sin necesidad de privilegios de ejecución adicionales. No se necesita interacción del usuario para la explotación. ID de parche: WCNCR00384543; ID de problema: MSV-1727."
    }
  ],
  "lastModified": "2026-06-17T07:06:03.343",
  "sourceIdentifier": "security@mediatek.com"
}