CVE-2024-25073
MEDIUM EPSS 30.4%
Published Sep 10, 20241y ago · Modified Jun 17, 20262w ago
5.9 CVSS 3.1
Published Sep 10, 2024 1y ago
Last Modified Jun 17, 2026 2w ago
Description
An issue was discovered in Samsung Semiconductor Mobile Processor and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos W930, Exynos Modem 5123, Exynos Modem 5300. The baseband software does not properly check a pointer specified by the CC (Call Control module), which can lead to Denial of Service (Untrusted Pointer Dereference).
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Attack Vector Network
Attack Complexity High
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High
Threat Intelligence
EPSS Exploit Probability
30.4% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-476 NULL Pointer Dereference Memory Safety
Affected Products 32
| Vendor | Product | Version | Range |
|---|---|---|---|
| samsung | exynos_1080_firmware | * | any |
| samsung | exynos_1080 | * | any |
| samsung | exynos_1280_firmware | * | any |
| samsung | exynos_1280 | * | any |
| samsung | exynos_1330_firmware | * | any |
| samsung | exynos_1330 | * | any |
| samsung | exynos_1380_firmware | * | any |
| samsung | exynos_1380 | * | any |
| samsung | exynos_2100_firmware | * | any |
| samsung | exynos_2100 | * | any |
| samsung | exynos_2200_firmware | * | any |
| samsung | exynos_2200 | * | any |
| samsung | exynos_850_firmware | * | any |
| samsung | exynos_850 | * | any |
| samsung | exynos_9110_firmware | * | any |
| samsung | exynos_9110 | * | any |
| samsung | exynos_980_firmware | * | any |
| samsung | exynos_980 | * | any |
| samsung | exynos_9820_firmware | * | any |
| samsung | exynos_9820 | * | any |
| samsung | exynos_9825_firmware | * | any |
| samsung | exynos_9825 | * | any |
| samsung | exynos_990_firmware | * | any |
| samsung | exynos_990 | * | any |
| samsung | exynos_modem_5123_firmware | * | any |
| samsung | exynos_modem_5123 | * | any |
| samsung | exynos_modem_5300_firmware | * | any |
| samsung | exynos_modem_5300 | * | any |
| samsung | exynos_w920_firmware | * | any |
| samsung | exynos_w920 | * | any |
| samsung | exynos_w930_firmware | * | any |
| samsung | exynos_w930 | * | any |
References 2
- semiconductor.samsung.com https://semiconductor.samsung.com/support/quality-support/product-security-updates/
- semiconductor.samsung.com https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-25073/
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.