CVE-2023-20702: High severity android vulnerability
In 5G NRLC, there is a possible invalid memory access due to lack of error handling. This could lead to remote denial of service, if UE received invalid 1-byte rlc sdu, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00921261; Issue ID: MOLY01128895.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-20702?
CVE-2023-20702 is a vulnerability in 5G NRLC that could lead to remote denial of service due to a possible invalid memory access.
How severe is CVE-2023-20702?
CVE-2023-20702 has a severity rating of 7.5 (high).
Which software is affected by CVE-2023-20702?
CVE-2023-20702 affects Mediatek Nr15, Mediatek Nr16, and Mediatek Nr17.
Is Google Android vulnerable to CVE-2023-20702?
Google Android is vulnerable to CVE-2023-20702 if it is running on Mediatek Nr15, Mediatek Nr16, or Mediatek Nr17.
How can CVE-2023-20702 be fixed?
To fix CVE-2023-20702, apply the patch with ID MOLY00921261 provided by Mediatek.