5.5

CVE-2024-27366

An issue was discovered in Samsung Mobile Processor, Wearable Processor Exynos Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 1480, Exynos W920, Exynos W930. In the function slsi_rx_scan_done_ind(), there is no input validation check on a length coming from userspace, which can lead to a potential heap over-read.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Samsung ≫ Exynos 980 Firmware Version -
   Samsung ≫ Exynos 980 Version -
Samsung ≫ Exynos 850 Firmware Version -
   Samsung ≫ Exynos 850 Version -
Samsung ≫ Exynos 1080 Firmware Version -
   Samsung ≫ Exynos 1080 Version -
Samsung ≫ Exynos 1280 Firmware Version -
   Samsung ≫ Exynos 1280 Version -
Samsung ≫ Exynos 1380 Firmware Version -
   Samsung ≫ Exynos 1380 Version -
Samsung ≫ Exynos 1330 Firmware Version -
   Samsung ≫ Exynos 1330 Version -
Samsung ≫ Exynos 1480 Firmware Version -
   Samsung ≫ Exynos 1480 Version -
Samsung ≫ Exynos W920 Firmware Version -
   Samsung ≫ Exynos W920 Version -
Samsung ≫ Exynos W930 Firmware Version -
   Samsung ≫ Exynos W930 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.057
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
MITRE 4.4 0.8 3.6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://semiconductor.samsung.com/support/quality-support/product-security-updates/
Vendor Advisory
https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-27366/
Vendor Advisory