Impact
In Android cellular modem firmware, a heap buffer overflow can trigger an out-of-bounds write, enabling remote code execution without any user interaction to exploit, making it a serious risk for affected devices.
Affected Systems
Devices running Android information is not supplied in the advisory, so all current Android releases that include the vulnerable modem firmware are potentially impacted.
Risk and Exploitability
With a CVSS score of 8 the vulnerability is considered high severity. The EPSS score is < 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers could exploit the overflow from a proximity or adjacent context, as the description indicates a “proximity/adjacent” code execution scenario. Because no privileges are required and user interaction is unnecessary, the risk is significant if the exploit succeeds.
OpenCVE Enrichment