Improper Input Validation Vulnerability in CertByte by Samsung
CVE-2023-21480

8.5HIGH

Key Information:

Vendor

Samsung

Vendor
CVE Published:
3 September 2025

What is CVE-2023-21480?

An improper input validation vulnerability exists in CertByte prior to SMR Apr-2023 Release 1, allowing local attackers to perform unauthorized privileged actions. This flaw highlights the importance of thorough input validation to prevent potential exploitation. Users are advised to update to the latest version to mitigate risks associated with this vulnerability.

Affected Version(s)

Samsung Mobile Devices SMR Apr-2023 Release in Select Android 11, 12, 13 devices

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-21480 : Improper Input Validation Vulnerability in CertByte by Samsung