PT-2024-7445 · Samsung · Samsung Android
Published
2024-05-07
·
Updated
2025-02-10
·
CVE-2024-20865
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Samsung Android mobile devices (affected versions not specified)
Samsung Android mobile devices versions prior to SMR May-2024 Release 1
Description:
The issue is related to weaknesses in the authentication procedure of the bootloader component in Samsung Android mobile devices. This can allow an attacker to bypass authentication and potentially impact the confidentiality, integrity, and availability of protected information. The vulnerability can be exploited by physical attackers to flash arbitrary images.
Recommendations:
For versions prior to SMR May-2024 Release 1, update to the SMR May-2024 Release 1 or later to resolve the issue.
As a temporary workaround, consider restricting physical access to the device to minimize the risk of exploitation.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Samsung Android