VDB
CVE-2023-32889
CVE-2023-32889
PUBLISHED
CVSS 8.600000381469727 HIGH
In Modem IMS Call UA, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01161825; Issue ID: MOLY01161825 (MSV-895).
EPSS 0.41% · 35.2th percentile
Risk Scores
CVSS 4.0
8.600000381469727
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.41%
35.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| MediaTek, Inc. | MT2735, MT6813, MT6833, MT6833P, MT6835, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6877T, MT6878, MT6879, MT6880, MT6883, MT6885, MT6886, MT6889, MT6890, MT6891, MT6893, MT6895, MT6895T, MT6896, MT6897, MT6980, MT6980D, MT6983T, MT6983W, MT6983Z, MT6985, MT6985T, MT6989, MT6990 | Modem NR15, NR16, and NR17, Modem NR15, NR16, and NR17 |
| android | 11.0, 12.0, 11.0 |
Timeline
- Jan 2, 2024 CVE Published
- Jan 3, 2024 EPSS Score
- Jan 3, 2024 PoC Published
- Jan 22, 2024 PoC Published
- Feb 1, 2024 EPSS Score
- Mar 1, 2024 EPSS Score
- Mar 30, 2024 EPSS Score
- May 26, 2024 EPSS Score
- Jun 24, 2024 EPSS Score
- Jul 23, 2024 EPSS Score
- Aug 21, 2024 EPSS Score
- Sep 19, 2024 EPSS Score