CVE-2024-54982
Severity CVSS v4.0:
Pending analysis
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
19/12/2024
Last modified:
16/01/2025
Description
An issue in Quectel BC25 with firmware version BC25PAR01A06 allows attackers to bypass authentication via a crafted NAS message. NOTE: Quectel disputes this because the issue is in the chipset supply chain and is not localized to one or more Quectel products.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL