PT-2023-9618 · Samsung · Samsung Android

CVE-2024-20820

·

Published

2023-11-28

·

Updated

2024-10-17

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Samsung mobile devices versions prior to SMR Feb-2024 Release 1
Description The issue is related to improper input validation in the bootloader, which allows local privileged attackers to cause an Out-Of-Bounds read. This can potentially impact the confidentiality and availability of protected information. The vulnerability is associated with a buffer overflow in the bootloader component of Samsung Android mobile devices.
Recommendations For versions prior to SMR Feb-2024 Release 1, update to the SMR Feb-2024 Release 1 or later to resolve the issue. As a temporary workaround, consider restricting access to the bootloader to minimize the risk of exploitation.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-08823
CVE-2024-20820

Affected Products

Samsung Android