Nr17
Vendor:
First CVE: Oct 2, 2023 · Active for 2 years
48
Total CVEs
More Total CVEs than 97% of tracked products
12.0
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Nr17 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 2, 2023
2 years ago
Most Recent CVE
Mar 2, 2026
144 days ago
CVE Severity & Scoring
Nr1748 CVEs
48%
42%
10%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local5 (10.4%)
Network36 (75.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network7 (14.6%)
Attack Complexity
Low42 (87.5%)
High6 (12.5%)
Unknown0 (0.0%)
User Interaction
None45 (93.8%)
Unknown0 (0.0%)
Required3 (6.3%)
Privileges Required
Low6 (12.5%)
High5 (10.4%)
None37 (77.1%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (48 CVEs).
48 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-20708HIGH In Modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station | Sep 1, 2025 | 8.8 | 29 | NO | NO |
CVE-2025-20634CRITICAL In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution, if a UE has connected to a rogue base station controlled | Feb 3, 2025 | 9.8 | 28 | NO | NO |
CVE-2026-20434HIGH In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station co | Mar 2, 2026 | 7.5 | 27 | NO | NO |
CVE-2025-20727HIGH In Modem, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station co | Nov 4, 2025 | 8.1 | 27 | NO | NO |
CVE-2024-20082CRITICAL In Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interac | Aug 14, 2024 | 9.8 | 27 | NO | NO |
CVE-2023-32874CRITICAL In Modem IMS Stack, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. | Jan 2, 2024 | 9.8 | 27 | NO | NO |
CVE-2025-20704HIGH In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station co | Sep 1, 2025 | 8.0 | 26 | NO | NO |
CVE-2024-20067CRITICAL In modem, there is a possible out of bounds write due to improper input invalidation. This could lead to remote denial of service with no additional execution privileges needed. Us | Jun 3, 2024 | 9.8 | 26 | NO | NO |
CVE-2025-20726HIGH In Modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station | Nov 4, 2025 | 7.5 | 25 | NO | NO |
CVE-2024-20039HIGH In modem protocol, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. U | Apr 1, 2024 | 8.8 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (48 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (48 CVEs).
Media Mentions
Signals from CVEs in this product scope (48 CVEs).
Top CNAs Publishing CVEs For Nr17
Top CWEs
Versions
No cataloged versions.