ZeroHour

CVE-2022-21744

CVSS 3.1
9.8 critical
EPSS
3%p88
Published
()
Modified
Description

In Modem 2G RR, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decoding GPRS Packet Neighbour Cell Data (PNCD) improper neighbouring cell size with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00810064; Issue ID: ALPS06641626.

Vendors
mediatek
Products
lr11, lr12, lr12a, lr13, lr9, nr15, nr16
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.