CVE-2024-39431
published 2024-09-27CVE-2024-39431: In UMTS RLC driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of service with System execution…
PriorityP417medium4.5CVSS 3.1
AVAACLPRHUINSUCNINAH
EPSS
0.18%
7.3th percentile
In UMTS RLC driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of service with System execution privileges needed.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| unisoc_technologies_co_ltd | sc7731e_sc9832e_sc9863a_t310_t606_t612_t616_t610_t618_t760_t770_t820_s8000 | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jv5j-9qxg-rrh2: In UMTS RLC driver, there is a possible out of bounds write due to a missing bounds check
ghsa_unreviewed·2024-09-27
CVE-2024-39431 [HIGH] CWE-787 GHSA-jv5j-9qxg-rrh2: In UMTS RLC driver, there is a possible out of bounds write due to a missing bounds check
In UMTS RLC driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of service with System execution privileges needed.
Android
CVE-2024-39431: Modem
vendor_android·2024-09-01·CVSS 8.3
CVE-2024-39431 [HIGH] CVE-2024-39431: Modem
Android Security Bulletin 2024-09-01
CVE: CVE-2024-39431
Severity: HIGH
Component: Modem
References: A-349917018
U-2638126 *
No detection rules found.
No public exploits indexed.
Securelist
A vehicle's head unit hacked via its modem
blogs_securelist·2025-12-16·CVSS 8.3
CVE-2024-39431 [HIGH] A vehicle's head unit hacked via its modem
Table of Contents
- Introduction
- Acquiring the modem firmware
- Remote access to the modem (CVE-2024-39431)
- Gaining persistence in the system
Authors
- Alexander Kozlov
- Sergey Anufrienko
- Kaspersky ICS CERT
## Introduction
Imagine you’re cruising down the highway in your brand-new electric car. All of a sudden, the massive multimedia display fills with Doom, the iconic 3D shooter game. It completely replaces the navigation map or the controls menu, and you realize someone is playing it remotely right now. This is not a dream or an overactive imagination – we’ve demonstrated that it’s a perfectly realistic scenario in today’s world.
The internet of things now plays a significant role in the modern world. Not only are smartphones and laptops connected to the network, but also f
Securelist
God Mode On: how we attacked a vehicle’s head unit modem
blogs_securelist·2025-12-16·CVSS 8.3
CVE-2024-39431 [HIGH] God Mode On: how we attacked a vehicle’s head unit modem
Table of Contents
Introduction
Acquiring the modem firmware
Remote access to the modem (CVE-2024-39431)
Gaining persistence in the system
Authors
Alexander Kozlov
Sergey Anufrienko
Kaspersky ICS CERT
## Introduction
Imagine you’re cruising down the highway in your brand-new electric car. All of a sudden, the massive multimedia display fills with Doom, the iconic 3D shooter game. It completely replaces the navigation map or the controls menu, and you realize someone is playing it remotely right now. This is not a dream or an overactive imagination – we’ve demonstrated that it’s a perfectly realistic scenario in today’s world.
The internet of things now plays a significant role in the modern world. Not only are smartphones and laptops connected to the network, but also factories,
2024-09-27
Published