Impact
A missing bounds check in the MediaTek chipset modem can cause a system crash, providing an attacker control over a rogue base station a means to deny service remotely. The flaw requires no special privileges or user interaction, enabling straightforward exploitation from a compromised UE’s perspective. The impact is loss of connectivity and potential service interruption for affected devices, though no integrity or confidentiality compromise is indicated.
Affected Systems
The vulnerability affects devices powered by MediaTek chipsets as sold by MediaTek, Inc. The affected firmware or modem software variants are not enumerated in the data, so any firmware build with the identified bounds check omission could be at risk.
Risk and Exploitability
The CVSS score is 5.3, and EPSS data is unavailable, but the lack of required privileges and absence of user interaction suggest a moderate exploitability. The CVE is not listed in CISA’s KEV catalog, indicating there are no confirmed widespread exploitation incidents yet. An attacker could trigger the crash by sending specially crafted packets from a rogue base station to a connected UE, causing a denial of service without further actions.
OpenCVE Enrichment