PT-2023-3382 · Samsung · Exynos 9110+5

Published

2023-02-07

·

Updated

2025-02-07

·

CVE-2023-29085

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Exynos Modem 5123 Exynos Modem 5300 Exynos 980 Exynos 1080 Exynos 9110 Exynos Auto T5123
Description The issue is related to a buffer overflow when decoding an SIP status line, potentially allowing a remote attacker to cause a denial of service due to memory corruption caused by insufficient parameter validation.
Recommendations For Exynos Modem 5123, consider disabling the SIP status line decoding functionality until a patch is available. For Exynos Modem 5300, restrict access to the SIP status line decoding module to minimize the risk of exploitation. For Exynos 980, Exynos 1080, Exynos 9110, and Exynos Auto T5123, avoid using the SIP status line decoding function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2023-03549
CVE-2023-29085

Affected Products

Exynos 1080
Exynos 9110
Exynos 980
Exynos Auto T5123
Exynos Modem 5123
Exynos Modem 5300