PT-2023-18248 · Unknown · Shannon Baseband

Dawuge

·

Published

2023-05-04

·

Updated

2023-05-11

·

CVE-2023-21494

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Shannon baseband versions prior to SMR May-2023 Release 1
Description The issue is related to a potential buffer overflow vulnerability in the auth API, specifically in the mm Authentication.c file. This could allow remote attackers to cause invalid memory access.
Recommendations For versions prior to SMR May-2023 Release 1, update to the SMR May-2023 Release 1 or later to resolve the issue. As a temporary workaround, consider restricting access to the auth API in mm Authentication.c to minimize the risk of exploitation.

Fix

RCE

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2023-21494

Affected Products

Shannon Baseband