[CVE-2021-25487] Samsung Mobile Devices Out-of-Bounds Read Vulnerability

SecurityDesk
2023.06.29 00:00 조회 17

CISA KEV 정보

취약점명Samsung Mobile Devices Out-of-Bounds Read Vulnerability
설명Samsung mobile devices contain an out-of-bounds read vulnerability within the modem interface driver due to a lack of boundary checking of a buffer in set_skb_priv(), leading to remote code execution by dereference of an invalid function pointer.
조치사항Apply updates per vendor instructions or discontinue use of the product if updates are unavailable
랜섬웨어 캠페인 악용Unknown
CWECWE-125
등록일 (KEV)2023-06-29
조치 기한2023-07-20
추가 참고https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=10; https://nvd.nist.gov/vuln/detail/CVE-2021-25487

NVD 상세 정보

CVSS v3.1: 7.3 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
CVSS v2.0: 4.6 AV:L/AC:L/Au:N/C:P/I:P/A:P

설명: Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dereference of invalid function pointer.

CWE: CWE-125 | CWE-125

참조

This product uses the NVD API but is not endorsed or certified by the NVD.



바로 가기

IT 도구 서랍

→ Unix: 2025-01-15T09:30:00
→ 날짜: 1736934600

→ ASCII: ABC
→ 문자: 65 66 67

ASCII 코드표 — 클릭하면 입력란에 추가

DecHex약어설명
DecHex문자
DecHex문자

→ 유니코드: 홍길동
→ 문자: \ud64d\uae38\ub3d9