Double Free Validation Issue in Samsung mPOS TUI Trustlet
CVE-2023-21500

5.5MEDIUM

Key Information:

Vendor
Samsung
Vendor
CVE Published:
4 May 2023

Summary

A double free validation vulnerability exists in the setPinPadImages function of the mPOS TUI trustlet prior to the May-2023 SMR Release 1. This flaw may allow local attackers to exploit the trustlet's memory space, potentially exposing sensitive information or enabling unauthorized access. It's critical to apply the latest security updates to mitigate the risks associated with this vulnerability.

Affected Version(s)

Samsung Mobile Devices Select Android 13 devices

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.