Impact
An error handling flaw in the modem subsystem of MediaTek chipsets can cause a system crash. The defect allows a rogue base station to trigger the crash remotely without requiring user interaction or elevated privileges, resulting in a denial of service. The vulnerability is categorized as CWE-617, reflecting improper error handling.
Affected Systems
The flaw affects MediaTek, Inc. MediaTek chipsets. No specific version range is listed in the advisory, so all current and future Modem firmware on these chipsets is potentially vulnerable until the patch is applied.
Risk and Exploitability
The low EPSS score of < 1% indicates a very small likelihood of exploitation, but the lack of user interaction and the ability to cause a crash via a rogue base station suggest that attackers who control a base station can still launch a remote denial of service. The vulnerability is not listed in CISA's KEV catalog. The CVSS score of 6.5 indicates a medium severity risk for affected devices.
OpenCVE Enrichment