Impact
The vulnerability stems from improper input validation in the Cellular Modem component, which can trigger a denial of service without the need for elevated privileges. The flaw allows a remote attacker to cause the modem to become unresponsive or crash, potentially disrupting cellular connectivity. According to the description, user interaction is not required for exploitation, meaning an attacker could initiate the exploit from an adjacent or nearby location. The likely attack vector is a remote, proximal or adjacent attack that targets the modem’s input processing.
Affected Systems
The affected product is the Android Cellular Modem component of Google Android devices. No specific device models or version numbers are listed in the available data, so all devices that incorporate this modem component are potentially impacted until an official patch is applied.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity vulnerability. The EPSS score is < 1%, indicating that the probability of exploitation is very low. The flaw is not currently listed in the CISA KEV catalog. Exploitation requires no user interaction and no additional privileges, which lowers the barrier to attack but results in a loss of connectivity rather than a compromise of the device or data. Attackers would need to deliver malformed input to the modem, which may be achievable through broadcast or other input channels that the modem processes.
OpenCVE Enrichment