CVE-2026-20479: High severity Modem vulnerability
In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00741071; Issue ID: MSV-7620.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch MOLY00741071
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20479?
The severity of CVE-2026-20479 is high with a CVSS score of 7.5.
What risks are associated with CVE-2026-20479?
CVE-2026-20479 poses a risk of remote denial of service due to a possible out of bounds read.
How can CVE-2026-20479 be exploited?
CVE-2026-20479 can be exploited by an attacker through a rogue base station without requiring special execution privileges.
Who is affected by CVE-2026-20479?
Users connected to a rogue base station controlled by an attacker are at risk from CVE-2026-20479.
What is the recommended fix for CVE-2026-20479?
To address CVE-2026-20479, a patch from the software provider should be applied as detailed in their security bulletin.