Skip to content
COOEY

EXPOSURES › CVE-2021-25372

CVE-2021-25372

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-06-29 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-25372 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

Samsung mobile devices had an improperly checked boundary in their DSP driver, leading to out-of-bounds memory access and active exploitation in the wild.

An improper boundary check in Samsung's DSP driver allowed for out-of-bounds memory access, actively exploited and linked to KEV. DIB organizations using Samsung mobile devices must immediately patch to prevent potential data compromise and compliance failures (NIST 800-171 controls 3.1.1, 3.1.2). Verify patching status and consider device restrictions.

Shame score — The vulnerability's active exploitation demonstrates a failure to implement basic secure coding practices, and the widespread use of Samsung devices amplifies the potential impact.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Samsung mobile devices contain an improper boundary check vulnerability within DSP driver that allows for out-of-bounds memory access.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.