← back
CVE-2023-52533mediumCWE-475

CVE-2023-52533

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.3epss 0.4%
exploitation probability
0.4%top 72% of all CVEs
observed exploitation
nono source reports it
In short

A modem component fails to properly handle errors, which can expose sensitive information to remote attackers without requiring special privileges. This happens because the code doesn't correctly check for error conditions.

Technical detail

CWE-475 undefined behavior stems from improper error handling in modem-ps-nas-ngmm, allowing remote information disclosure via crafted inputs. No elevated privileges required; the vulnerability resides in missing or incorrect error validation paths that permit data leakage.

Summary generated and translated by AI from the official description.
In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L