CVE-2026-20504
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00755024; Issue ID: MSV-7865.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.19%
- CWE
- CWE-617
- Published
- 2026-09-07
- Last modified
- 2026-09-07
Affected products
- MediaTek, Inc. MediaTek chipset
- MediaTek, Inc. MediaTek chipset
- MediaTek, Inc. MediaTek chipset
- MediaTek, Inc. MediaTek chipset
- MediaTek, Inc. MediaTek chipset
- MediaTek, Inc. MediaTek chipset
- MediaTek, Inc. MediaTek chipset
- MediaTek, Inc. MediaTek chipset
Weakness type
Related vulnerabilities
- CVE-2026-82068 — Persistent Fatal Assertion Crash in MongoDB Server via Crafted Retryable Write Commands Leads to Denial of Service
- CVE-2026-82065 — Insufficient Validation of Storage Configuration Options in MongoDB Server Leads to Persistent Denial of Service via Corrupted Metadata
- CVE-2026-82064 — Unauthenticated Denial of Service in MongoDB Server via Assertion Failure in Read Concern Processing on Replica Set Members
- CVE-2026-82059 — Improper Access Restriction of Internal Aggregation Expression in MongoDB Server Leads to Assertion Failure and Denial of Service
- CVE-2026-82052 — $regexFindAll may crash mongod server when byte-matching multi-byte UTF-8 chars
- CVE-2026-86317 — ggml-org llama.cpp RPC Server ggml-rpc.cpp deserialize_tensor assertion
- CVE-2026-20503 — In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote...
- CVE-2026-31911 — abort() in libpcap before 1.10.7 on an invalid BPF opcode