CVE-2023-32886
📋 TL;DR
This vulnerability allows remote attackers to cause denial of service on affected devices by exploiting an out-of-bounds write in the Modem IMS SMS UA component. No user interaction or special privileges are required for exploitation. This affects devices using MediaTek chipsets with vulnerable modem firmware.
💻 Affected Systems
- Devices with MediaTek chipsets using vulnerable modem firmware
📦 What is this software?
Nr15 by Mediatek
Nr16 by Mediatek
Nr17 by Mediatek
⚠️ Risk & Real-World Impact
Worst Case
Remote attacker could crash the modem subsystem, causing complete loss of cellular connectivity including voice, SMS, and data services until device restart.
Likely Case
Remote denial of service affecting cellular connectivity, potentially disrupting emergency services and critical communications.
If Mitigated
With proper network segmentation and access controls, impact limited to isolated network segments.
🎯 Exploit Status
Exploitation requires sending specially crafted SMS/IMS messages to vulnerable devices
🛠️ Fix & Mitigation
✅ Official Fix
Patch Version: Firmware with patch ID MOLY00730807
Vendor Advisory: https://corp.mediatek.com/product-security-bulletin/January-2024
Restart Required: Yes
Instructions:
1. Contact device manufacturer for firmware updates 2. Apply modem firmware update 3. Reboot device to activate patched firmware
🔧 Temporary Workarounds
Network-level SMS filtering
allFilter suspicious SMS/IMS messages at network level
Disable IMS services
allTemporarily disable IMS/VoLTE services if not required
🧯 If You Can't Patch
- Segment cellular devices on separate network segments
- Implement strict network monitoring for abnormal SMS traffic patterns
🔍 How to Verify
Check if Vulnerable:
Check modem firmware version against MediaTek security bulletin; contact device manufacturer for specific version information
Check Version:
Device-specific commands vary by manufacturer; typically available through engineering mode or manufacturer diagnostic tools
Verify Fix Applied:
Verify modem firmware has been updated to version containing patch MOLY00730807
📡 Detection & Monitoring
Log Indicators:
- Modem crash logs
- Abnormal SMS/IMS message processing errors
- Cellular service disruption events
Network Indicators:
- Unusual SMS traffic patterns
- SMS messages with malformed headers or content
SIEM Query:
Search for modem subsystem crashes or cellular service disruption events in device logs