9.8

CVE-2023-24033

The Samsung Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T512 baseband modem chipsets do not properly check format types specified by the Session Description Protocol (SDP) module, which can lead to a denial of service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Samsung ≫ Exynos Modem 5300 Firmware Version -
   Samsung ≫ Exynos Modem 5300 Version -
Samsung ≫ Exynos Modem 5123 Firmware Version -
   Samsung ≫ Exynos Modem 5123 Version -
Samsung ≫ Exynos 980 Firmware Version -
   Samsung ≫ Exynos 980 Version -
Samsung ≫ Exynos 1080 Firmware Version -
   Samsung ≫ Exynos 1080 Version -
Samsung ≫ Exynos Auto T5123 Firmware Version -
   Samsung ≫ Exynos Auto T5123 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 33.17% 0.982
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
MITRE 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://semiconductor.samsung.com/support/quality-support/product-security-updates/
Vendor Advisory
https://semiconductor.samsung.com/processor/modem/
Product
http://packetstormsecurity.com/files/172137/Shannon-Baseband-accept-type-SDP-Attribute-Memory-Corruption.html