CVE-2023-43551Improper Authentication in INC Snapdragon

Severity
7.5HIGHNVD
EPSS
0.1%
top 73.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 3

Description

Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

CVEListV5qualcomm_inc/snapdragon240 versions+239

🔴Vulnerability Details

1
GHSA
GHSA-4h56-hghf-36cj: Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Securi2024-06-03

📋Vendor Advisories

2
Android
CVE-2023-43551: Closed-source component2024-06-01
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: SSL Module (cURL) — CVE-2022-435512023-04-15