CVE-2022-26446
Published: 08 November 2022
Summary
CVE-2022-26446 is a high-severity Reachable Assertion (CWE-617) vulnerability in Mediatek Lr12A. Its CVSS base score is 7.5 (High).
Operationally, ranked in the top 23.8% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2022-31005
Vulnerability details
In Modem 4G RRC, there is a possible system crash due to improper input validation. This could lead to remote denial of service, when concatenating improper SIB12 (CMAS message), with no additional execution privileges needed. User interaction is not needed…
more
for exploitation. Patch ID: MOLY00867883; Issue ID: ALPS07274118.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.