> Source: [sk184123](https://support.checkpoint.com/results/sk/sk184123)

# sk184123 - Android Devices Flagged Non-Compliant in Harmony Mobile Dashboard due to CVE-2024-20129 

| Property | Value |
|----------|-------|
| Solution ID | sk184123 |
| Date Created | 2025-10-02 |
| Last Modified | 2025-10-08 |
| Technical Level | General |
| Products | Mobile Security |
| Versions | Cloud |

## Symptoms

- * Harmony Mobile flags all Android devices (including Samsung S23, S24, and Sony XQ-EC72) as non-compliant as **CVE-2024-20129** is rated as a **Medium** threat.
* Devices are fully updated but fail compliance checks.
* Attempts to set CVE-2024-20129 to **Low** risk in the Global policy revert after saving.
* Administrators cannot exclude CVE-2024-20129 using the policy interface.
* Compliance integration with Microsoft Intune Mobile Device Management (MDM) relies on Harmony Mobile to pass threat level. Any threat level above **Low** flags the device as non-compliant.
* Administrators are forced to disable device compliance checking in Microsoft Azure conditional access policies, increasing risk exposure.

## Cause

Harmony Mobile cannot detect chipsets (for example, MediaTek) on Android devices. CVE-2024-20129 affects only MediaTek chipsets on Android versions 13, 14, and 15. However, the Harmony Mobile platform applies this vulnerability to all devices running these OS versions, regardless of their actual chipset, causing false positives.  
Additionally, UI and backend limitations also prevented policy changes, such as downgrading the CVE risk level or excluding it, compounding the compliance issue.

## Solution

Harmony Mobile now includes the following improvements:

* Risk calculations by Common Vulnerability Scoring System (CVSS) score exclude Common Vulnerabilities and Exposures (CVEs) with specific policy exceptions.
* Administrators can exclude CVEs in Device policy by setting the CVE risk level to **None**.

**To resolve the issue** :  

1. Ensure the device is running the latest version of Harmony Mobile Protect app.
2. Access the Harmony Mobile dashboard and set the risk level for **CVE-2024-20129** :
   1. Go to your policy \> **Device** \> **OS Vulnerabilities**.
   2. In the CVE risk level list, add **CVE-2024-20129** and set its **Risk Level** as **Low** or **None** .   
      ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk184123/Set_CVE_Risk202510071239271.png)
   3. Save the policy changes and verify that the risk level is applied.
3. Verify Device Compliance:
   1. Confirm that affected devices pass compliance check in Harmony Mobile:  
      Go to **Forensics** \> **Events \& Alerts** and select **View By Device Risk** .  
      ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk184123/Check_Device_Compliance202510071244492.png)
   2. Confirm that affected devices pass compliance check in Microsoft Intune MDM.
   3. Make sure that device compliance check is re-enabled in Azure conditional access policies.
4. Monitor for False Positives:  
   Monitor devices for any false positives related to CVE-2024-20129, especially on non-MediaTek chipsets.  
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk184123/Monitor_Device202510071126401.png)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
