CVE-2024-22006
MEDIUMCVSS 5.3/10EPSS 0.23%
Last modified
CVE-2024-22006 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. OOB read in the TMU plugin that allows for memory disclosure in the power management subsystem of the device.. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
OOB read in the TMU plugin that allows for memory disclosure in the power management subsystem of the device.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | 13.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-22006?
OOB read in the TMU plugin that allows for memory disclosure in the power management subsystem of the device.
How severe is CVE-2024-22006?
CVE-2024-22006 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 0.23% probability of exploitation in the next 30 days.
How do I fix CVE-2024-22006?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-21993SnapCenter versions prior to 5.0p1 are susceptible to a vuln…6.5
- CVE-2024-21994StorageGRID (formerly StorageGRID Webscale) versions prior t…4.3
- CVE-2024-2200The Contact Form by BestWebSoft plugin for WordPress is vuln…6.1
- CVE-2024-22002CORSAIR iCUE 5.9.105 with iCUE Murals on Windows allows unpr…7.8
- CVE-2024-22004Due to length check, an attacker with privilege access on a …7.7
- CVE-2024-22005there is a possible Authentication Bypass due to improperly …8.4
- CVE-2024-22007In constraint_check of fvp.c, there is a possible out of bou…6.2
- CVE-2024-22008In config_gov_time_windows of tmu.c, there is a possible out…7.8
- CVE-2024-22009In init_data of , there is a possible out of bounds write du…7.1
- CVE-2024-2201A cross-privilege Spectre v2 vulnerability allows attackers …4.7
- CVE-2024-22010In dvfs_plugin_caller of fvp.c, there is a possible out of b…5.5
- CVE-2024-22011In ss_ProcessRejectComponent of ss_MmConManagement.c, there …7.5
Are you affected by CVE-2024-22006?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
