ZeroHour

CVE-2023-43551

CVSS 3.1
7.5 high
EPSS
<1%p17
Published
()
Modified
Description

Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.

Vendors
qualcomm
Products
315 5g iot modem firmware, 9205 lte modem firmware, 9206 lte modem firmware, 9207 lte modem firmware, apq8017 firmware, apq8037 firmware, aqt1000 firmware, ar6003 firmware, ar8035 firmware, c-v2x 9150 firmware, csra6620 firmware, csra6640 firmware
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.