Lucene search

K
cve[email protected]CVE-2023-30738
HistoryOct 04, 2023 - 4:15 a.m.

CVE-2023-30738

2023-10-0404:15:13
web.nvd.nist.gov
27
cve-2023-30738
uefi firmware
galaxy book
security
smm
memory corruption
nvd

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.5 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

An improper input validation in UEFI Firmware prior to Firmware update Oct-2023 Release in Galaxy Book, Galaxy Book Pro, Galaxy Book Pro 360 and Galaxy Book Odyssey allows local attacker to execute SMM memory corruption.

Affected configurations

NVD
Node
samsunggalaxy_book_firmwareRange<oct-2023
AND
samsunggalaxy_bookMatch-
Node
samsunggalaxy_book_pro_firmwareRange<oct-2023
AND
samsunggalaxy_book_proMatch-
Node
samsunggalaxy_book_pro_360_firmwareRange<oct-2023
AND
samsunggalaxy_book_pro_360Match-
Node
samsunggalaxy_book_odyssey_firmwareRange<oct-2023
AND
samsunggalaxy_book_odysseyMatch-

CNA Affected

[
  {
    "vendor": "Samsung Mobile",
    "product": "Galaxy Book, Galaxy Book Pro, Galaxy Book Pro 360 and Galaxy Book Odyssey",
    "versions": [
      {
        "status": "unaffected",
        "version": "Firmware update Oct-2023 Release"
      }
    ],
    "defaultStatus": "affected"
  }
]

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.5 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Related for CVE-2023-30738