CVE-2023-32846 is a denial-of-service vulnerability affecting MediaTek 5G modems, stemming from improper error handling when processing malformed RRC messages. This critical flaw allows for remote denial of service without requiring user interaction or additional execution privileges, as reflected by its CVSS score of 7.5 (High). While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community attention and media coverage, including reports on the broader "5Ghoul" attack impacting 5G modems. Organizations using affected MediaTek products should prioritize applying the provided patch (MOLY01128524).
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:mediatek:nr15:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:mediatek:nr16:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:mediatek:nr17:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.