PT-2024-22770 · Samsung · Exynos 1280+15
Published
2024-07-09
·
Updated
2024-07-11
·
CVE-2024-29153
CVSS v3.1
8.1
High
| Vector | AC:H/AV:N/A:H/C:H/I:H/PR:N/S:U/UI:N |
Name of the Vulnerable Software and Affected Versions
Samsung Mobile Processor, Wearable Processor, and Modems versions Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos W930, Exynos Modem 5123, and Exynos Modem 5300
Description
A vulnerability was discovered that involves incorrect authorization of LTE NAS messages. This issue leads to downgrading to lower network generations and repeated Denial of Service (DDOS) attacks.
Recommendations
For Samsung Mobile Processor, Wearable Processor, and Modems versions Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos W930, Exynos Modem 5123, and Exynos Modem 5300, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Exynos 1080
Exynos 1280
Exynos 1330
Exynos 1380
Exynos 2100
Exynos 2200
Exynos 850
Exynos 9110
Exynos 980
Exynos 9820
Exynos 9825
Exynos 990
Exynos Modem 5123
Exynos Modem 5300
Exynos W920
Exynos W930