7.5

CVE-2019-20601

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos7570, 7580, 7870, 7880, and 8890 chipsets) software. RKP memory corruption causes an arbitrary write to protected memory. The Samsung ID is SVE-2019-13921-2 (May 2019).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GoogleAndroid Version7.0
   SamsungExynos 7570 Version-
   SamsungExynos 7580 Version-
   SamsungExynos 7870 Version-
   SamsungExynos 7880 Version-
   SamsungExynos 8890 Version-
GoogleAndroid Version7.1.0
   SamsungExynos 7570 Version-
   SamsungExynos 7580 Version-
   SamsungExynos 7870 Version-
   SamsungExynos 7880 Version-
   SamsungExynos 8890 Version-
GoogleAndroid Version7.1.1
   SamsungExynos 7570 Version-
   SamsungExynos 7580 Version-
   SamsungExynos 7870 Version-
   SamsungExynos 7880 Version-
   SamsungExynos 8890 Version-
GoogleAndroid Version7.1.2
   SamsungExynos 7570 Version-
   SamsungExynos 7580 Version-
   SamsungExynos 7870 Version-
   SamsungExynos 7880 Version-
   SamsungExynos 8890 Version-
GoogleAndroid Version8.0
   SamsungExynos 7570 Version-
   SamsungExynos 7580 Version-
   SamsungExynos 7870 Version-
   SamsungExynos 7880 Version-
   SamsungExynos 8890 Version-
GoogleAndroid Version8.1
   SamsungExynos 7570 Version-
   SamsungExynos 7580 Version-
   SamsungExynos 7870 Version-
   SamsungExynos 7880 Version-
   SamsungExynos 8890 Version-
GoogleAndroid Version9.0
   SamsungExynos 7570 Version-
   SamsungExynos 7580 Version-
   SamsungExynos 7870 Version-
   SamsungExynos 7880 Version-
   SamsungExynos 8890 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.09% 0.234
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.