Possible System Crash Due to Improper Input Validation
CVE-2023-32890
7.5HIGH
Key Information:
- Vendor
- MediaTek
- Vendor
- CVE Published:
- 2 January 2024
Summary
A flaw exists in the MediaTek modem EMM due to inadequate input validation processes. This vulnerability allows attackers to potentially cause a system crash, resulting in a remote denial of service condition. Critically, the exploitation of this vulnerability does not require any user interaction, making it a significant security concern for users of the affected products. The issue has been documented under Patch ID: MOLY01183647 and pertains to Issue ID: MOLY01183647 (MSV-963).
Affected Version(s)
MT2731, MT6767, MT6768, MT6769, MT6769T, MT6769Z, MT8786 Modem LR12A
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved