CVE-2023-32841 is a high-severity vulnerability affecting MediaTek 5G modems, stemming from improper error handling. This flaw allows for a remote denial of service (DoS) attack without requiring user interaction or elevated privileges, simply by sending malformed RRC messages. The CVSS score of 7.5 reflects its network-based attack vector and high impact on availability. While not currently listed in CISA's KEV catalog and lacking public exploit code, it has garnered significant community attention and media coverage, including its association with the "5Ghoul" attack.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:mediatek:nr15:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:mediatek:nr16:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:mediatek:nr17:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.