Out of Bounds Write Vulnerability in MediaTek Modem IMS SMS UA
CVE-2023-32886

7.5HIGH

Summary

The vulnerability in MediaTek's Modem IMS SMS UA stems from a potential out-of-bounds write caused by a failure to implement proper bounds checks. This flaw enables an attacker to exploit the vulnerability remotely, resulting in a denial of service without requiring any additional execution privileges. Notably, exploitation does not necessitate user interaction, making it a concerning risk for the affected systems. Immediate attention to the patch (ID: MOLY00730807) is advised to mitigate potential security threats.

Affected Version(s)

MT2735, MT6813, MT6833, MT6833P, MT6835, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6877T, MT6878, MT6879, MT6880, MT6883, MT6885, MT6886, MT6889, MT6890, MT6891, MT6893, MT6895, MT6895T, MT6896, MT6897, MT6980, MT6980D, MT6983T, MT6983W, MT6983Z, MT6985, MT6985T, MT6989, MT6990, MT8673, MT8675, MT8676, MT8791, MT8791T, MT8792, MT8796, MT8797, MT8798 Modem NR15, NR16, and NR17

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.