CVE-2025-20647
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Mar 3, 2025
CWE ID 476
Summary
CVE-2025-20647 is a vulnerability affecting Modem software that allows for a remote denial of service (DoS) attack. The issue arises from a missing bounds check, leading to a system crash. An attacker can exploit this vulnerability by connecting a UE to a rogue base station under their control, requiring no additional execution privileges or user interaction. The patch IDs for this issue are MOLY00791311 and MOLY01067019, with the issue ID being MSV-2721.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Mediatek Inc.