Intra-object Overflow Vulnerability in Samsung Mobile Chipset and Baseband Modem
CVE-2023-26076

9.8CRITICAL

Key Information:

Vendor
Samsung
Vendor
CVE Published:
13 March 2023

Summary

A vulnerability has been identified within the Samsung Mobile Chipset and Baseband Modem family, specifically impacting the Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. This issue arises from an intra-object overflow within the 5G SM message codec, caused by a lack of adequate parameter validation when decoding reserved options. This deficiency poses a risk as it can lead to potential exploitation if not addressed. Mitigating strategies and updates from Samsung are essential to enhance security and protect users.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.