Show filters
37 Total Results
Displaying 11-20 of 37
Sort by:
Attacker Value
Unknown

CVE-2023-52348

Disclosure Date: April 08, 2024 (last updated April 10, 2024)
In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
0
Attacker Value
Unknown

CVE-2023-52347

Disclosure Date: April 08, 2024 (last updated April 10, 2024)
In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
0
Attacker Value
Unknown

CVE-2023-52346

Disclosure Date: April 08, 2024 (last updated April 10, 2024)
In modem driver, there is a possible system crash due to improper input validation. This could lead to local information disclosure with System execution privileges needed
0
Attacker Value
Unknown

CVE-2023-52344

Disclosure Date: April 08, 2024 (last updated April 10, 2024)
In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed
0
Attacker Value
Unknown

CVE-2023-52343

Disclosure Date: April 08, 2024 (last updated April 10, 2024)
In SecurityCommand message after as security has been actived., there is a possible improper input validation. This could lead to remote information disclosure no additional execution privileges needed
0
Attacker Value
Unknown

CVE-2023-52342

Disclosure Date: April 08, 2024 (last updated April 10, 2024)
In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed
0
Attacker Value
Unknown

CVE-2023-52341

Disclosure Date: April 08, 2024 (last updated April 10, 2024)
In Plaintext COUNTER CHECK message accepted before AS security activation, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed
0
Attacker Value
Unknown

CVE-2023-33898

Disclosure Date: July 12, 2023 (last updated February 25, 2025)
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Attacker Value
Unknown

CVE-2022-38100

Disclosure Date: September 01, 2022 (last updated February 24, 2025)
The CMS800 device fails while attempting to parse malformed network data sent by a threat actor. A threat actor with network access can remotely issue a specially formatted UDP request that will cause the entire device to crash and require a physical reboot. A UDP broadcast request could be sent that causes a mass denial-of-service attack on all CME8000 devices connected to the same network.
Attacker Value
Unknown

CVE-2022-3027

Disclosure Date: September 01, 2022 (last updated February 24, 2025)
The CMS8000 device does not properly control or sanitize the SSID name of a new Wi-Fi access point. A threat actor could create an SSID with a malicious name, including non-standard characters that, when the device attempts connecting to the malicious SSID, the device can be exploited to write arbitrary files or display incorrect information.