Buffer Access Vulnerability in Samsung mTower
CVE-2022-40760
7.5HIGH
What is CVE-2022-40760?
A Buffer Access with Incorrect Length Value vulnerability exists in the TEE_MACUpdate function of the Samsung mTower product through version 0.3.0. This vulnerability can be exploited by trusted applications invoking TEE_MACUpdate with an excessively large chunkSize parameter, potentially leading to a Denial of Service (DoS). Such an attack could impact the availability and functionality of the system, making it critical for users to apply proper security measures and updates.