VDB

CVE-2023-32889

CVE-2023-32889 PUBLISHED CVSS 8.600000381469727 HIGH

In Modem IMS Call UA, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01161825; Issue ID: MOLY01161825 (MSV-895).

EPSS 0.41% · 35.2th percentile

Risk Scores

CVSS 4.0
8.600000381469727
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.41%
35.2th percentile

Affected Products

VendorProductVersions
MediaTek, Inc.MT2735, MT6813, MT6833, MT6833P, MT6835, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6877T, MT6878, MT6879, MT6880, MT6883, MT6885, MT6886, MT6889, MT6890, MT6891, MT6893, MT6895, MT6895T, MT6896, MT6897, MT6980, MT6980D, MT6983T, MT6983W, MT6983Z, MT6985, MT6985T, MT6989, MT6990Modem NR15, NR16, and NR17, Modem NR15, NR16, and NR17
googleandroid11.0, 12.0, 11.0

Timeline

  • Jan 2, 2024 CVE Published
  • Jan 3, 2024 EPSS Score
  • Jan 3, 2024 PoC Published
  • Jan 22, 2024 PoC Published
  • Feb 1, 2024 EPSS Score
  • Mar 1, 2024 EPSS Score
  • Mar 30, 2024 EPSS Score
  • May 26, 2024 EPSS Score
  • Jun 24, 2024 EPSS Score
  • Jul 23, 2024 EPSS Score
  • Aug 21, 2024 EPSS Score
  • Sep 19, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›