PT-2020-8688 · Samsung · Samsung Mobile Devices With N(7.X)+1
Published
2020-04-08
·
Updated
2020-04-09
·
CVE-2018-21044
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Samsung mobile devices with N(7.x) software
Samsung mobile devices with O(8.0) software
Description
An issue was discovered that leads to a buffer overflow in the sem Trustlet, resulting in arbitrary TEE code execution.
Recommendations
For Samsung mobile devices with N(7.x) software, update to a version that addresses the buffer overflow issue in the sem Trustlet.
For Samsung mobile devices with O(8.0) software, update to a version that addresses the buffer overflow issue in the sem Trustlet.
As a temporary workaround, consider restricting access to the sem Trustlet to minimize the risk of exploitation.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Samsung Mobile Devices With N(7.X)
Samsung Mobile Devices With O(8.0)