Heap Out-of-Bounds Write Vulnerability in Samsung Bootloader
CVE-2023-21489

6.8MEDIUM

Key Information:

Vendor
Samsung
Vendor
CVE Published:
4 May 2023

Summary

A heap out-of-bounds write vulnerability exists in the Samsung bootloader prior to the Security Maintenance Release (SMR) May 2023 Release 1. This flaw allows a physical attacker to exploit the system, potentially leading to the execution of arbitrary code on affected devices. The vulnerability undermines the security of the boot process, emphasizing the importance of keeping firmware up to date to mitigate security risks.

Affected Version(s)

Samsung Mobile Devices Selected Android 11, 12, 13 Qualcomm devices

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.