Improper Input Validation in RPMB LDFW by Samsung Mobile
CVE-2022-23432

6.4MEDIUM

Key Information:

Vendor
Samsung
Vendor
CVE Published:
11 February 2022

Summary

An improper input validation vulnerability exists in the SMC_SRPMB_WSM handler of the RPMB LDFW prior to the SMR February 2022 Release 1. This flaw could allow an attacker to exploit the vulnerability by performing arbitrary memory writes, potentially leading to unauthorized code execution within affected devices. Users should ensure their devices are updated to the latest firmware to mitigate any potential risks associated with this vulnerability.

Affected Version(s)

Samsung Mobile Devices with Exynos chipsets P(9.0), Q(10.0), R(11.0), S(12.0) devices with selected Exynos chipsets

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.