Vulnerability

CVE-2022-21744

Component: CELLULAR
Location: FIRMWARE
In Modem 2G RR, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decoding GPRS Packet Neighbour Cell Data (PNCD) improper neighbouring cell size with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00810064; Issue ID: ALPS06641626.

Impact

Severity (Manufact.)

HIGH

Severity (NIST)

9.8

Severity (Android)

N/A

Chipsets

117

Devices

1925

Affected Hardware

NameAlso known asManufacturer
MT6735P
MediaTek
MT6735M
MediaTek
MT6735
MediaTek
MT6737
MediaTek
MT6737T
MediaTek
MT6739
MediaTek
MT6750
MediaTek
MT6750N
MediaTek
MT6750T
MediaTek
MT6750S
MediaTek
117 of 117 row(s) shown.

Rows per page

Page 1 of 12

Timeline

Introduced (est):
Apr 1, 2015
Reported:
Unknown
Advisory Published:
Jul 4, 2022
CVE Published:
Jul 6, 2022
Android Patch Level:
Jul 2022
For more information and a detailed analysis of the data presented on this website, please see our paper, to be presented at NDSS'25.
Follow us on Twitter