4.4

CVE-2023-21492

Warning

Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.

Data is provided by the National Vulnerability Database (NVD)
SamsungAndroid Version11.0 Update-
SamsungAndroid Version11.0 Updatesmr-apr-2021-r1
SamsungAndroid Version11.0 Updatesmr-apr-2022-r1
SamsungAndroid Version11.0 Updatesmr-apr-2023-r1
SamsungAndroid Version11.0 Updatesmr-aug-2021-r1
SamsungAndroid Version11.0 Updatesmr-aug-2022-r1
SamsungAndroid Version11.0 Updatesmr-dec-2020-r1
SamsungAndroid Version11.0 Updatesmr-dec-2021-r1
SamsungAndroid Version11.0 Updatesmr-dec-2022-r1
SamsungAndroid Version11.0 Updatesmr-feb-2021-r1
SamsungAndroid Version11.0 Updatesmr-feb-2022-r1
SamsungAndroid Version11.0 Updatesmr-feb-2023-r1
SamsungAndroid Version11.0 Updatesmr-jan-2021-r1
SamsungAndroid Version11.0 Updatesmr-jan-2022-r1
SamsungAndroid Version11.0 Updatesmr-jan-2023-r1
SamsungAndroid Version11.0 Updatesmr-jul-2021-r1
SamsungAndroid Version11.0 Updatesmr-jul-2022-r1
SamsungAndroid Version11.0 Updatesmr-jun-2021-r1
SamsungAndroid Version11.0 Updatesmr-jun-2022-r1
SamsungAndroid Version11.0 Updatesmr-mar-2021-r1
SamsungAndroid Version11.0 Updatesmr-mar-2022-r1
SamsungAndroid Version11.0 Updatesmr-mar-2023-r1
SamsungAndroid Version11.0 Updatesmr-may-2021-r1
SamsungAndroid Version11.0 Updatesmr-may-2022-r1
SamsungAndroid Version11.0 Updatesmr-nov-2021-r1
SamsungAndroid Version11.0 Updatesmr-nov-2022-r1
SamsungAndroid Version11.0 Updatesmr-oct-2021-r1
SamsungAndroid Version11.0 Updatesmr-oct-2022-r1
SamsungAndroid Version11.0 Updatesmr-sep-2021-r1
SamsungAndroid Version11.0 Updatesmr-sep-2022-r1
SamsungAndroid Version12.0 Update-
SamsungAndroid Version12.0 Updatesmr-apr-2022-r1
SamsungAndroid Version12.0 Updatesmr-apr-2023-r1
SamsungAndroid Version12.0 Updatesmr-aug-2022-r1
SamsungAndroid Version12.0 Updatesmr-dec-2021-r1
SamsungAndroid Version12.0 Updatesmr-dec-2022-r1
SamsungAndroid Version12.0 Updatesmr-feb-2022-r1
SamsungAndroid Version12.0 Updatesmr-feb-2023-r1
SamsungAndroid Version12.0 Updatesmr-jan-2022-r1
SamsungAndroid Version12.0 Updatesmr-jan-2023-r1
SamsungAndroid Version12.0 Updatesmr-jul-2022-r1
SamsungAndroid Version12.0 Updatesmr-jun-2022-r1
SamsungAndroid Version12.0 Updatesmr-mar-2022-r1
SamsungAndroid Version12.0 Updatesmr-mar-2023-r1
SamsungAndroid Version12.0 Updatesmr-may-2022-r1
SamsungAndroid Version12.0 Updatesmr-nov-2021-r1
SamsungAndroid Version12.0 Updatesmr-nov-2022-r1
SamsungAndroid Version12.0 Updatesmr-oct-2022-r1
SamsungAndroid Version12.0 Updatesmr-sep-2022-r1
SamsungAndroid Version13.0 Update-
SamsungAndroid Version13.0 Updatesmr-apr-2022-r1
SamsungAndroid Version13.0 Updatesmr-apr-2023-r1
SamsungAndroid Version13.0 Updatesmr-aug-2022-r1
SamsungAndroid Version13.0 Updatesmr-dec-2021-r1
SamsungAndroid Version13.0 Updatesmr-dec-2022-r1
SamsungAndroid Version13.0 Updatesmr-feb-2022-r1
SamsungAndroid Version13.0 Updatesmr-feb-2023-r1
SamsungAndroid Version13.0 Updatesmr-jan-2022-r1
SamsungAndroid Version13.0 Updatesmr-jan-2023-r1
SamsungAndroid Version13.0 Updatesmr-jul-2022-r1
SamsungAndroid Version13.0 Updatesmr-jun-2022-r1
SamsungAndroid Version13.0 Updatesmr-mar-2022-r1
SamsungAndroid Version13.0 Updatesmr-mar-2023-r1
SamsungAndroid Version13.0 Updatesmr-may-2022-r1
SamsungAndroid Version13.0 Updatesmr-nov-2021-r1
SamsungAndroid Version13.0 Updatesmr-nov-2022-r1
SamsungAndroid Version13.0 Updatesmr-oct-2022-r1
SamsungAndroid Version13.0 Updatesmr-sep-2022-r1

19.05.2023: CISA Known Exploited Vulnerabilities (KEV) Catalog

Samsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability

Vulnerability

Samsung mobile devices running Android 11, 12, and 13 contain an insertion of sensitive information into log file vulnerability that allows a privileged, local attacker to conduct an address space layout randomization (ASLR) bypass.

Description

Apply updates per vendor instructions.

Required actions
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.49% 0.629
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.4 0.8 3.6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
mobile.security@samsung.com 4.4 0.8 3.6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.