PT-2024-18728 · Samsung · Samsung Mobile Devices

Published

2024-05-06

·

Updated

2024-05-07

·

CVE-2024-20821

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Samsung Mobile Devices (affected versions not specified)
Description A vulnerability allows local attackers to reconfigure OTP, enabling them to transit into RMA mode, which disables security features. This attack requires additional privilege to control the Trusted Execution Environment (TEE). The issue is related to a lack of immutable root of trust in OTP hardware.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2024-20821

Affected Products

Samsung Mobile Devices