Possible System Crash Due to Improper Input Validation
CVE-2023-32890

7.5HIGH

Key Information:

Vendor
MediaTek
Vendor
CVE Published:
2 January 2024

Summary

A flaw exists in the MediaTek modem EMM due to inadequate input validation processes. This vulnerability allows attackers to potentially cause a system crash, resulting in a remote denial of service condition. Critically, the exploitation of this vulnerability does not require any user interaction, making it a significant security concern for users of the affected products. The issue has been documented under Patch ID: MOLY01183647 and pertains to Issue ID: MOLY01183647 (MSV-963).

Affected Version(s)

MT2731, MT6767, MT6768, MT6769, MT6769T, MT6769Z, MT8786 Modem LR12A

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.