CVE-2023-32843Reachable Assertion in Google Android

Severity
7.5HIGHNVD
EPSS
0.6%
top 30.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 4
Latest updateFeb 1

Description

In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01130204; Issue ID: MOLY01130204 (MSV-849).

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

🔴Vulnerability Details

1
GHSA
GHSA-wx4f-36r2-29rm: In 5G Modem, there is a possible system crash due to improper error handling2023-12-04

📋Vendor Advisories

1
Android
CVE-2023-32843: 5G Modem2024-02-01

🕵️Threat Intelligence

1
Bleepingcomputer
New 5Ghoul attack impacts 5G phones with Qualcomm, MediaTek chips2023-12-08