CVE-2023-32843
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 1.4%
exploitation probability
1.4%top 31% of all CVEs
observed exploitation
nono source reports it
In short
A 5G modem can crash when it receives specially crafted network messages because it doesn't properly handle errors. An attacker can remotely cause this crash without needing special access or user action, disrupting the device's connectivity.
Technical detail
The 5G modem lacks proper error handling for malformed RRC (Radio Resource Control) messages, allowing a remote attacker to trigger a system crash via a network-based vector without elevated privileges or user interaction. The vulnerability results in denial of service by making the modem unresponsive.
Summary generated and translated by AI from the official description.
In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01130204; Issue ID: MOLY01130204 (MSV-849).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H