Lucene search

K
nvd[email protected]NVD:CVE-2023-31114
HistoryJun 07, 2023 - 9:15 p.m.

CVE-2023-31114

2023-06-0721:15:13
CWE-669
web.nvd.nist.gov
4
samsung
exynos modem
vulnerability
resource transfer
sim
status
crafted application

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

9

Confidence

High

EPSS

0.001

Percentile

35.3%

An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300. Incorrect resource transfer between spheres can cause unintended querying of the SIM status via a crafted application.

Affected configurations

Nvd
Node
samsungexynos_5123Match-
AND
samsungexynos_5123_firmwareMatch-
Node
samsungexynos_5300Match-
AND
samsungexynos_5300_firmwareMatch-
VendorProductVersionCPE
samsungexynos_5123-cpe:2.3:h:samsung:exynos_5123:-:*:*:*:*:*:*:*
samsungexynos_5123_firmware-cpe:2.3:o:samsung:exynos_5123_firmware:-:*:*:*:*:*:*:*
samsungexynos_5300-cpe:2.3:h:samsung:exynos_5300:-:*:*:*:*:*:*:*
samsungexynos_5300_firmware-cpe:2.3:o:samsung:exynos_5300_firmware:-:*:*:*:*:*:*:*

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

9

Confidence

High

EPSS

0.001

Percentile

35.3%

Related for NVD:CVE-2023-31114