PT-2025-19331 · Modem · Modem

Published

2025-05-05

·

Updated

2026-02-17

·

CVE-2025-20667

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Modem (affected versions not specified)
Description The issue is related to incorrect error handling in the Modem, which could lead to remote information disclosure if a UE has connected to a rogue base station controlled by the attacker. No additional execution privileges are needed, and user interaction is not required for exploitation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Inadequate Encryption Strength

Weakness Enumeration

Related Identifiers

CVE-2025-20667

Affected Products

Modem