Impact
The vulnerability is an out-of-bounds read in the Modem firmware of MediaTek chipsets caused by a missing bounds check. Because the check is absent, an attacker who can control the traffic from a rogue base station may read memory outside the intended buffer, resulting in a denial-of-service condition on the user equipment. The flaw is categorized as CWE-125 and does not require local or elevated privileges, nor any user interaction, to be triggered.
Affected Systems
Affected systems are devices that incorporate MediaTek chipsets manufactured by MediaTek, Inc. The Modem component is the vulnerable area. No specific firmware or hardware version numbers are listed in the advisory, so any device using the affected Modem firmware may be impacted.
Risk and Exploitability
The CVSS score is 7.5, indicating high severity, while the EPSS score is < 1%, reflecting a low exploitation probability. The flaw can be exploited remotely by any UE that connects to a rogue base station under attacker control. The vulnerability is not listed in the CISA KEV catalog, which suggests no known widespread exploitation yet. Nevertheless, because the exploit requires no privilege escalation and does not need user interaction, it poses a high risk of denial of service to consumers and operators alike. Prompt patching is advised.
OpenCVE Enrichment