Samsung Exynos Processors Vulnerable to Denial of Service Attack
CVE-2024-39343

7HIGH

Key Information:

Vendor
Samsung
Vendor
CVE Published:
2 December 2024

Summary

A vulnerability identified in Samsung's Exynos mobile and wearable processors, specifically in the MM (Mobility Management) module of the baseband software, permits an improper validation of length checks. This oversight could potentially lead to a Denial of Service, affecting the operation of devices utilizing the Exynos 2100, 1280, 2200, 1330, 1380, 1480, 2400, along with Modem 5123 and Modem 5300. Users of these processors should be aware of this security flaw and take appropriate measures to mitigate any risks associated with its exploitation.

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.