CVE-2024-40674
Last modified
CVE-2024-40674 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. In validateSsid of WifiConfigurationUtil.java, there is a possible way to overflow a system configuration file due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
In validateSsid of WifiConfigurationUtil.java, there is a possible way to overflow a system configuration file due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | 14.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-40674?
How severe is CVE-2024-40674?
How do I fix CVE-2024-40674?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-40669In TBD of TBD, there is a possible use after free due to a r…8.4
- CVE-2024-4067The NPM package `micromatch` prior to 4.0.8 is vulnerable to…5.3
- CVE-2024-40670In TBD of TBD, there is a possible use after free due to a r…8.4
- CVE-2024-40671In DevmemIntChangeSparse2 of devicemem_server.c, there is a …7.8
- CVE-2024-40672In onCreate of ChooserActivity.java, there is a possible way…8.4
- CVE-2024-40673In Source of ZipFile.java, there is a possible way for an at…6.5
- CVE-2024-40675In parseUriInternal of Intent.java, there is a possible infi…7.5
- CVE-2024-40676In checkKeyIntent of AccountManagerService.java, there is a …7.7
- CVE-2024-40677In shouldSkipForInitialSUW of AdvancedPowerUsageDetail.java,…8.4
- CVE-2024-40679IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Se…5.5
- CVE-2024-4068The NPM package `braces`, versions prior to 3.0.3, fails to …7.5
- CVE-2024-40680IBM MQ 9.3 CD and 9.4 LTS/CD could allow a local user to cau…5.5
Are you affected by CVE-2024-40674?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
