CVE-2023-32843

high

Description

In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01130204; Issue ID: MOLY01130204 (MSV-849).

References

https://asset-group.github.io/disclosures/5ghoul/

https://corp.mediatek.com/product-security-bulletin/December-2023

Details

Source: Mitre, NVD

Published: 2023-12-04

Updated: 2025-05-29

Named Vulnerability: 5Ghoul

Risk Information

CVSS v2

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

Severity: High

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Severity: High

EPSS

EPSS: 0.02474