← back
CVE-2022-20083

CVE-2022-20083

EPSS 2.2%
In short

A flaw in Modem 2G/3G CC allows an attacker to write data outside allowed memory boundaries when decoding certain network signals, potentially taking control of the modem without needing special permissions or user action.

Technical detail

Missing bounds check in combined FACILITY decoding within Modem 2G/3G CC enables out-of-bounds write via network-sourced input. Attack vector is remote (no user interaction required), requires no elevated privileges, and can achieve arbitrary code execution on the affected modem.

Summary generated and translated by AI from the official description.
In Modem 2G/3G CC, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decoding combined FACILITY with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00803883; Issue ID: MOLY00803883.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →