Sceawere
Vulnerability Detail
CVE-2026-20534UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Modem Out-of-Bounds Read Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 17h ago
- Vendor
- MediaTek, Inc.
- Product
- MediaTek chipset
- Attack Type
- CWE-125 Out-of-bounds Read
- Vector String
- CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
In Modem, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01797547; Issue ID: MSV-9155.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-05T02:16:52.273Z",
"pubdate": "2026-10-05T02:16:52.273Z",
"executiveSummary": "This vulnerability involves an out-of-bounds (OOB) read condition identified within the Modem software component, specifically tracked under Issue ID MSV-9155 and Patch ID MOLY01797547.\nThe root cause is an incorrect bounds check, which allows an attacker to access memory locations outside the allocated buffer boundaries.\nThe vulnerability poses a significant risk to affected devices, as it facilitates a remote denial-of-service (DoS) condition.\nExploitation is feasible when a User Equipment (UE) device connects to a rogue base station controlled by an adversary.\nThe attack vector is characterized by zero-click capability, requiring no user interaction and no elevated execution privileges to trigger the flaw.\nThe primary risk implication is the forced termination of modem services, resulting in a loss of network connectivity and potential system instability.",
"technicalDetails": "The vulnerability resides in the input validation logic within the Modem firmware/software stack. Specifically, the component responsible for processing base station signaling messages fails to correctly enforce boundary conditions during memory read operations.\nWhen a UE establishes a Radio Resource Control (RRC) connection or performs cell selection, it processes incoming data packets from the base station. The vulnerability occurs when the modem parses malformed or maliciously crafted Protocol Data Units (PDUs) that contain length indicators inconsistent with the actual payload size.\nDue to the flawed bounds check, the modem's processing logic fails to validate the offset against the allocated buffer size. When the processor attempts to access memory at the offset specified by the rogue base station, it performs an OOB read. If the pointer arithmetic results in an address beyond the legitimate memory region, the modem may attempt to access protected or unmapped memory.\nThe attack flow proceeds as follows: First, the attacker deploys a rogue base station (e.g., an IMSI catcher or a malicious small cell) configured to broadcast parameters that force the target UE to initiate a connection. Second, the attacker transmits a specially crafted signaling message to the UE. Third, the UE's modem receives this message and triggers the faulty parsing routine. Fourth, the incorrect bounds check allows the parser to read beyond the intended buffer. Finally, the illegal memory access triggers an exception, leading to a kernel panic or a fatal error within the modem subsystem, effectively causing a DoS.\nBecause the modem typically runs with high privileges in a baseband processor environment, memory access violations are critical. In this scenario, the exploitation does not require pre-existing privileges on the UE, as the vulnerability is triggered via the air interface during the standard handshaking and message exchange protocols. The lack of proper input validation in the parser directly leads to service disruption, as the device is unable to recover from the faulted state without a reset of the modem component. No remote code execution (RCE) is explicitly confirmed by the vulnerability report, but the primitive of an OOB read is a significant security flaw that may facilitate further sophisticated exploitation or memory information disclosure."
}