CVE-2022-21744
CVE-2022-21744
In short
A vulnerability in 2G modem firmware allows attackers to write data beyond safe memory boundaries when processing certain mobile network signals, potentially enabling remote code execution without user interaction.
Technical detail
Out-of-bounds write in GPRS Packet Neighbour Cell Data (PNCD) decoding due to insufficient bounds validation on neighbouring cell size parameter. Remote attack vector requiring no privileges or user interaction; successful exploitation leads to arbitrary code execution in modem context.
Summary generated and translated by AI from the official description.
In Modem 2G RR, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decoding GPRS Packet Neighbour Cell Data (PNCD) improper neighbouring cell size with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00810064; Issue ID: ALPS06641626.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →