First published: Thu Sep 09 2021(Updated: )
In modem 2G RRM, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00500621; Issue ID: ALPS04964926.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
mediatek modem | =lr12a | |
mediatek modem | =lr13 | |
MediaTek MT6739 | ||
MediaTek MT6761 | ||
MediaTek MT6762M | ||
MediaTek MT6762D | ||
MediaTek MT6762M | ||
MediaTek MT6763 | ||
MediaTek MT6765 | ||
MediaTek MT6765T | ||
MediaTek MT6767 | ||
MediaTek MT6768 | ||
MediaTek MT6769 | ||
MediaTek MT6769T | ||
MediaTek MT6769Z | ||
MediaTek MT6771 | ||
MediaTek MT6779 | ||
MediaTek MT6783 | ||
MediaTek MT6785 | ||
MediaTek MT6785T |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-32485 is a vulnerability in modem 2G RRM that could lead to a system crash due to a heap buffer overflow, resulting in a remote denial of service attack.
The severity of CVE-2021-32485 is high, with a CVSS base score of 7.5.
CVE-2021-32485 can be exploited remotely without requiring any user interaction.
The affected software includes modem 2G RRM versions lr12a and lr13 by Mediatek.
Yes, a patch for CVE-2021-32485 is available with the Patch ID: MOLY00500621.