Skip to content
COOEY

EXPOSURES › CVE-2021-25487

CVE-2021-25487

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-06-29 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-25487 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Samsung mobile devices contained an out-of-bounds read vulnerability allowing remote code execution, and it's currently being exploited in the wild.

A lack of boundary checking in the modem interface driver of Samsung mobile devices allowed for remote code execution via an out-of-bounds read. DIB organizations using these devices face potential compromise and must immediately patch to mitigate risk and maintain CMMC compliance. Verify patching status and consider network segmentation to limit potential impact.

Shame score — The vulnerability's exploitation in the wild and potential for remote code execution demonstrates a significant failure in Samsung's secure coding practices and risk management.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Samsung mobile devices contain an out-of-bounds read vulnerability within the modem interface driver due to a lack of boundary checking of a buffer in set_skb_priv(), leading to remote code execution by dereference of an invalid function pointer.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.