NULL Pointer Dereference in Samsung Electronics mTower Product
CVE-2022-36621

7.5HIGH

Key Information:

Vendor
Samsung
Status
Vendor
CVE Published:
1 September 2022

Summary

A vulnerability has been identified in Samsung Electronics mTower, specifically in versions up to and including 0.3.0. This flaw arises due to a NULL pointer dereference in the function TEE_AllocateTransientObject. When triggered, this issue could lead to unexpected behavior or crashes within the application, potentially impacting its security and stability. It is important for users and administrators to address this vulnerability through an update or patch to ensure continued protection against potential exploits.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.