7.8

CVE-2022-22265

Warnung
An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GoogleAndroid Version9.0
   SamsungExynos Version-
GoogleAndroid Version10.0
   SamsungExynos Version-
GoogleAndroid Version11.0
   SamsungExynos Version-
GoogleAndroid Version12.0
   SamsungExynos Version-

18.09.2023: CISA Known Exploited Vulnerabilities (KEV) Catalog

Samsung Mobile Devices Use-After-Free Vulnerability

Schwachstelle

Samsung devices with selected Exynos chipsets contain a use-after-free vulnerability that allows malicious memory write and code execution.

Beschreibung

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.373
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
mobile.security@samsung.com 5 0.8 3.7
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L
CWE-703 Improper Check or Handling of Exceptional Conditions

The product does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the product.