CVE-2023-52344
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.3epss 0.4%
exploitation probability
0.4%top 72% of all CVEs
observed exploitation
nono source reports it
In short
A flaw in modem-ps-nas-ngmm allows attackers to access sensitive information remotely by exploiting improper error handling that causes undefined behavior. No special permissions are required to trigger this vulnerability.
Technical detail
The vulnerability stems from incorrect error handling in modem-ps-nas-ngmm (CWE-476: Null Pointer Dereference), enabling remote information disclosure without elevated privileges. The undefined behavior can be triggered remotely and may leak sensitive data through error responses or memory contents.
Summary generated and translated by AI from the official description.
In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected products
Unisoc (Shanghai) Technologies Co., Ltd. · T760/T770/T820/S8000