CVE-2023-32845 is a critical vulnerability affecting MediaTek 5G modems, stemming from improper error handling that can lead to a system crash. This flaw allows for remote denial of service (DoS) through specially crafted RRC messages, requiring no user interaction or additional privileges for exploitation. With a CVSS score of 7.5 (High), the attack vector is network-based with low complexity, resulting in high availability impact. While not currently listed in CISA's KEV catalog and lacking public exploit code, the vulnerability has garnered significant community discussion and media coverage, indicating its potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:mediatek:nr15:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:mediatek:nr16:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:mediatek:nr17:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.