Out-of-Bounds Array Access in Samsung Galaxy S6 Wi-Fi Driver
CVE-2018-14852

6.3MEDIUM

Key Information:

Vendor
Samsung
Vendor
CVE Published:
17 December 2018

Summary

The vulnerability arises from an out-of-bounds array access in the dhd_rx_frame function located in the bcmdhd4358 Wi-Fi driver for the Samsung Galaxy S6. This issue allows an attacker, who has achieved code execution on the Wi-Fi chip, to exploit improper validation of the network interface index presented by the firmware. Consequently, this can lead to invalid memory accesses within the operating system, potentially compromising the device's security and stability.

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.