CVE-2024-20860
NixOS vulnerability analysis and mitigation

Overview

Improper export of android application components vulnerability in TelephonyUI prior to SMR May-2024 Release 1 allows local attackers to reboot the device without proper permission. The vulnerability was discovered and reported on May 7, 2024, and was assigned CVE-2024-20860 by Samsung Mobile (Samsung Advisory).

Technical details

The vulnerability has been assigned a CVSS v3.1 Base Score of 3.3 (LOW) by NIST with vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L. Samsung Mobile assigned a slightly higher CVSS score of 4.0 (MEDIUM) with vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L. The vulnerability affects Samsung Android devices running version 14.0 and its various security patch levels (NVD).

Impact

If exploited, this vulnerability allows local attackers to reboot the device without having the proper permissions. This primarily affects the availability of the device, as indicated by the CVSS metrics showing impact only on availability (A:L) with no impact on confidentiality or integrity (NVD).

Exploitability

The vulnerability requires local access (AV:L) with low attack complexity (AC:L). According to NIST's assessment, it requires low privileges (PR:L) and no user interaction (UI:N) to exploit. However, Samsung's assessment indicates no privileges are required (PR:N) (NVD).

Mitigation and workarounds

The vulnerability has been patched in the Samsung Mobile Security Maintenance Release (SMR) May-2024 Release 1. Users should update their devices to this security patch level or later to mitigate the vulnerability (Samsung Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18713HIGH8.8
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18669HIGH8.8
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18235HIGH8.3
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-17420MEDIUM6.3
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18250MEDIUM5
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management