4.4
CVE-2023-21492
- EPSS 0.49%
- Veröffentlicht 04.05.2023 21:15:10
- Zuletzt bearbeitet 07.02.2025 15:05:07
- Quelle mobile.security@samsung.com
- Teams Watchlist Login
- Unerledigt Login
Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
19.05.2023: CISA Known Exploited Vulnerabilities (KEV) Catalog
Samsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability
SchwachstelleSamsung mobile devices running Android 11, 12, and 13 contain an insertion of sensitive information into log file vulnerability that allows a privileged, local attacker to conduct an address space layout randomization (ASLR) bypass.
BeschreibungApply updates per vendor instructions.
Erforderliche MaßnahmenTyp | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.49% | 0.629 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 4.4 | 0.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
mobile.security@samsung.com | 4.4 | 0.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
CWE-532 Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.