Impact
The vulnerability occurs when the Modem firmware performs improper input validation, which can cause a system crash. The resulting failure is a local denial of service that requires user execution privileges. Exploitation necessitates active user interaction; the attacker must supply crafted input while possessing local privileges on the device.
Affected Systems
Affected systems are MediaTek chipset devices. No specific product versions or firmware releases are listed in the advisory, so all devices using the vulnerable modem component should be assumed at risk until a patch is applied.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no known public exploitation. The attack vector is local, requiring a user with execution privileges and physical or logical access to the device. A successful exploit would lead to a system crash but would not provide remote code execution or further privilege escalation, resulting in a moderate risk for environments where device availability is critical and local privilege escalation is possible.
OpenCVE Enrichment