CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
61.9%
In Modem IMS Stack, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01161803; Issue ID: MOLY01161803 (MSV-893).
Vendor | Product | Version | CPE |
---|---|---|---|
mediatek | lr13 | - | cpe:2.3:o:mediatek:lr13:-:*:*:*:*:*:*:* |
mediatek | nr15 | - | cpe:2.3:o:mediatek:nr15:-:*:*:*:*:*:*:* |
mediatek | nr16 | - | cpe:2.3:o:mediatek:nr16:-:*:*:*:*:*:*:* |
mediatek | nr17 | - | cpe:2.3:o:mediatek:nr17:-:*:*:*:*:*:*:* |
mediatek | mt2735 | - | cpe:2.3:h:mediatek:mt2735:-:*:*:*:*:*:*:* |
mediatek | mt6779 | - | cpe:2.3:h:mediatek:mt6779:-:*:*:*:*:*:*:* |
mediatek | mt6781 | - | cpe:2.3:h:mediatek:mt6781:-:*:*:*:*:*:*:* |
mediatek | mt6783 | - | cpe:2.3:h:mediatek:mt6783:-:*:*:*:*:*:*:* |
mediatek | mt6785 | - | cpe:2.3:h:mediatek:mt6785:-:*:*:*:*:*:*:* |
mediatek | mt6785t | - | cpe:2.3:h:mediatek:mt6785t:-:*:*:*:*:*:*:* |
[
{
"vendor": "MediaTek, Inc.",
"product": "MT2735, MT6779, MT6781, MT6783, MT6785, MT6785T, MT6789, MT6813, MT6833, MT6833P, MT6835, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6877T, MT6878, MT6879, MT6880, MT6883, MT6885, MT6886, MT6889, MT6890, MT6891, MT6893, MT6895, MT6895T, MT6896, MT6897, MT6980, MT6980D, MT6983T, MT6983W, MT6983Z, MT6985, MT6985T, MT6989, MT6990",
"versions": [
{
"version": "Modem LR13 NR15, NR16, and NR17",
"status": "affected"
}
]
}
]