Lucene search

K
cvelistSamsung MobileCVELIST:CVE-2021-25516
HistoryDec 08, 2021 - 2:19 p.m.

CVE-2021-25516

2021-12-0814:19:55
CWE-703
Samsung Mobile
www.cve.org

6.4 Medium

CVSS3

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L

0.001 Low

EPSS

Percentile

35.0%

An improper check or handling of exceptional conditions in Exynos baseband prior to SMR Dec-2021 Release 1 allows attackers to track locations.

CNA Affected

[
  {
    "product": "Samsung Mobile Devices",
    "vendor": "Samsung Mobile",
    "versions": [
      {
        "lessThan": "SMR Dec-2021 Release 1",
        "status": "affected",
        "version": "P(9.0), Q(10.0), R(11.0) devices with selected Exynos chipsets",
        "versionType": "custom"
      }
    ]
  }
]

6.4 Medium

CVSS3

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L

0.001 Low

EPSS

Percentile

35.0%

Related for CVELIST:CVE-2021-25516