4.4
CVE-2023-21492
- EPSS 0.49%
- Published 04.05.2023 21:15:10
- Last modified 07.02.2025 15:05:07
- Source mobile.security@samsung.com
- Teams watchlist Login
- Open Login
Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.
Data is provided by the National Vulnerability Database (NVD)
19.05.2023: CISA Known Exploited Vulnerabilities (KEV) Catalog
Samsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability
VulnerabilitySamsung mobile devices running Android 11, 12, and 13 contain an insertion of sensitive information into log file vulnerability that allows a privileged, local attacker to conduct an address space layout randomization (ASLR) bypass.
DescriptionApply updates per vendor instructions.
Required actionsType | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.49% | 0.629 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 4.4 | 0.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
mobile.security@samsung.com | 4.4 | 0.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
CWE-532 Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.