Lucene search

K
cveSamsung MobileCVE-2022-39854
HistoryOct 07, 2022 - 3:15 p.m.

CVE-2022-39854

2022-10-0715:15:19
CWE-284
Samsung Mobile
web.nvd.nist.gov
29
3
cve-2022-39854
iommu
smr oct-2022
unauthorized access
secure memory
nvd

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0

Percentile

12.6%

Improper protection in IOMMU prior to SMR Oct-2022 Release 1 allows unauthorized access to secure memory.

Affected configurations

Nvd
Node
samsungexynosMatch-
AND
googleandroidMatch10.0
OR
googleandroidMatch11.0
OR
googleandroidMatch12.0
VendorProductVersionCPE
samsungexynos-cpe:2.3:h:samsung:exynos:-:*:*:*:*:*:*:*
googleandroid10.0cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:*
googleandroid11.0cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*
googleandroid12.0cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Samsung Mobile",
    "product": "Samsung Mobile Devices",
    "versions": [
      {
        "version": "Q(10), R(11), S(12)",
        "status": "affected",
        "lessThan": "SMR Oct-2022 Release 1",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0

Percentile

12.6%

Related for CVE-2022-39854