PT-2022-23515 · Samsung · Mtower

Published

2022-09-01

·

Updated

2022-09-07

·

CVE-2022-36622

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Samsung Electronics mTower versions 0.3.0 and earlier
Description The issue is related to a NULL pointer dereference via the function TEE GetObjectInfo1(). This indicates a problem where the software attempts to access memory through a null, or non-existent, pointer, which can lead to crashes or potentially allow an attacker to execute arbitrary code.
Recommendations For Samsung Electronics mTower versions 0.3.0 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2022-36622

Affected Products

Mtower