CVE-2021-25489

moderate-risk
Published 2021-10-06

Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug leading to kernel panic.

Do I need to act?

-
0.36% chance of exploitation
EPSS score — low exploit probability
!
CISA KEV: actively exploited in the wild
On the Known Exploited Vulnerabilities catalog — federal agencies must patch
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
3
CVSS 3.3/10 Low
LOCAL / LOW complexity

Affected Vendors

43
/ 100
moderate-risk
Severity 13/34 · Low
Exploitability 8/34 · Low
Exposure 22/34 · High