Skip to content
COOEY

EXPOSURES › CVE-2023-21492

CVE-2023-21492

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-05-19 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-21492 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

Samsung Android devices exposed sensitive info in logs, allowing ASLR bypass.

Samsung mobile devices running Android 11, 12, and 13 have a vulnerability that allows a privileged, local attacker to bypass Address Space Layout Randomization (ASLR), exposing sensitive information in log files. This can lead to unauthorized access and data exposure. DIB organizations should ensure their Android devices are updated to mitigate this risk.

Shame score — The vulnerability allowed an attacker to bypass ASLR, exposing sensitive information, which is a significant security risk.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Samsung mobile devices running Android 11, 12, and 13 contain an insertion of sensitive information into log file vulnerability that allows a privileged, local attacker to conduct an address space layout randomization (ASLR) bypass.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.