PT-2023-25935 · Samsung · Exynos 1380+11

Published

2023-09-07

·

Updated

2023-09-13

·

CVE-2023-37367

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Samsung Exynos Mobile Processor, Automotive Processor, and Modem versions Exynos 9820 through Exynos 2200 Samsung Exynos Mobile Processor, Automotive Processor, and Modem versions Exynos 1280 through Exynos 1380 Samsung Exynos Mobile Processor, Automotive Processor, and Modem version Exynos 1330 Samsung Exynos Mobile Processor, Automotive Processor, and Modem version Exynos 850 Samsung Exynos Mobile Processor, Automotive Processor, and Modem version Exynos 1080 Samsung Exynos Mobile Processor, Automotive Processor, and Modem version Exynos 2100 Samsung Exynos Modem 5123 Samsung Exynos Modem 5300 Samsung Exynos Auto T5123 Samsung Exynos Mobile Processor, Automotive Processor, and Modem version Exynos 980
Description An issue was discovered in the NAS Task of Samsung Exynos Mobile Processor, Automotive Processor, and Modem. The issue is related to an improperly implemented security check for standard, which can disallow desired services for a while via consecutive NAS messages.
Recommendations For Samsung Exynos Mobile Processor, Automotive Processor, and Modem version Exynos 9820, update to a version that includes the fix for the improperly implemented security check. For Samsung Exynos Mobile Processor, Automotive Processor, and Modem version Exynos 980, update to a version that includes the fix for the improperly implemented security check. For Samsung Exynos Mobile Processor, Automotive Processor, and Modem version Exynos 850, update to a version that includes the fix for the improperly implemented security check. For Samsung Exynos Mobile Processor, Automotive Processor, and Modem version Exynos 1080, update to a version that includes the fix for the improperly implemented security check. For Samsung Exynos Mobile Processor, Automotive Processor, and Modem version Exynos 2100, update to a version that includes the fix for the improperly implemented security check. For Samsung Exynos Mobile Processor, Automotive Processor, and Modem version Exynos 2200, update to a version that includes the fix for the improperly implemented security check. For Samsung Exynos Mobile Processor, Automotive Processor, and Modem version Exynos 1280, update to a version that includes the fix for the improperly implemented security check. For Samsung Exynos Mobile Processor, Automotive Processor, and Modem version Exynos 1380, update to a version that includes the fix for the improperly implemented security check. For Samsung Exynos Mobile Processor, Automotive Processor, and Modem version Exynos 1330, update to a version that includes the fix for the improperly implemented security check. For Samsung Exynos Modem 5123, update to a version that includes the fix for the improperly implemented security check. For Samsung Exynos Modem 5300, update to a version that includes the fix for the improperly implemented security check. For Samsung Exynos Auto T5123, update to a version that includes the fix for the improperly implemented security check. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-37367

Affected Products

Exynos 1080
Exynos 1280
Exynos 1330
Exynos 1380
Exynos 2100
Exynos 2200
Exynos 850
Exynos 980
Exynos 9820
Exynos Auto T5123
Exynos Modem 5123
Exynos Modem 5300