ID: CVE-2023-26076

Last Modified: March 17, 2023

An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. An intra-object overflow in the 5G SM message codec can occur due to insufficient parameter validation when decoding reserved options.

Twitter Activity

Tweets last week: 0

Remaining steady

Yahoo Activity

Yahoo results: 0

Remaining steady

EPSS History

Current EPSS Score: 0.00068

Remaining steady


Reddit Activity

Reddit Posts: 1

Remaining steady

Github Repos

Github Repos: 0

Remaining steady

Exploits

Found exploits:

Attack Vector: Network

Attack Complexity: Low

Privileges Required: None

User Interaction: None

Scope: Unchanged

Confidentiality: High

Integrity: High

Availability: High

Base Score: 9.8

Exploitability Score: 3.9

Impact Score: 5.9

CVSS V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Specialize CVSS-Score

CWE-120

Condition Configuration
AND
OR
OR
Alle Schwachstellen für samsung
OR
OR
Alle Schwachstellen für samsung
Condition Configuration
AND
OR
OR
Alle Schwachstellen für samsung
OR
OR
Alle Schwachstellen für samsung
Condition Configuration
AND
OR
OR
Alle Schwachstellen für samsung
OR
OR
Alle Schwachstellen für samsung
Condition Configuration
AND
OR
OR
Alle Schwachstellen für samsung
OR
OR
Alle Schwachstellen für samsung
Condition Configuration
AND
OR
OR
Alle Schwachstellen für samsung
OR
OR
Alle Schwachstellen für samsung
Date: March 17, 2023

CWE-ID: Not defined
Base Score V3: Not defined
Exploitability Score V3: Not defined
Impact Score V3: Not defined
Cvss Vector V3: Not defined
Reference:
added:
https://googleprojectzero.blogspot.com/2023/03/multiple-internet-to-baseband-remote-rce.html



Date: March 20, 2023

Reference:
added:
http://packetstormsecurity.com/files/171400/Shannon-Baseband-NrSmPcoCodec-Intra-Object-Overflow.html



                    <?xml version="1.0" ?>
<set operator="and">
    <set operator="or">
        <set operator="and">
            <set operator="or">
                <prop key="operating_system" value="cpe:2.3:o:samsung:exynos_1280_firmware:-:*:*:*:*:*:*:*"/>
            </set>
            <set operator="or">
                <prop key="device" value="cpe:2.3:h:samsung:exynos_1280:-:*:*:*:*:*:*:*"/>
            </set>
        </set>
        <set operator="and">
            <set operator="or">
                <prop key="operating_system" value="cpe:2.3:o:samsung:exynos_2200_firmware:-:*:*:*:*:*:*:*"/>
            </set>
            <set operator="or">
                <prop key="device" value="cpe:2.3:h:samsung:exynos_2200:-:*:*:*:*:*:*:*"/>
            </set>
        </set>
        <set operator="and">
            <set operator="or">
                <prop key="operating_system" value="cpe:2.3:o:samsung:exynos_modem_5123_firmware:-:*:*:*:*:*:*:*"/>
            </set>
            <set operator="or">
                <prop key="device" value="cpe:2.3:h:samsung:exynos_modem_5123:-:*:*:*:*:*:*:*"/>
            </set>
        </set>
        <set operator="and">
            <set operator="or">
                <prop key="operating_system" value="cpe:2.3:o:samsung:exynos_modem_5300_firmware:-:*:*:*:*:*:*:*"/>
            </set>
            <set operator="or">
                <prop key="device" value="cpe:2.3:h:samsung:exynos_modem_5300:-:*:*:*:*:*:*:*"/>
            </set>
        </set>
        <set operator="and">
            <set operator="or">
                <prop key="operating_system" value="cpe:2.3:o:samsung:exynos_auto_t5123_firmware:-:*:*:*:*:*:*:*"/>
            </set>
            <set operator="or">
                <prop key="device" value="cpe:2.3:h:samsung:exynos_auto_t5123:-:*:*:*:*:*:*:*"/>
            </set>
        </set>
    </set>
</set>

                  
                      <?xml version="1.0" ?>
<set operator="and">
    <set operator="or">
        <set operator="and">
            <set operator="or">
                <prop key="operating_system" value="cpe:2.3:o:samsung:exynos_1280_firmware:-:*:*:*:*:*:*:*"/>
            </set>
            <set operator="or">
                <prop key="device" value="cpe:2.3:h:samsung:exynos_1280:-:*:*:*:*:*:*:*"/>
            </set>
        </set>
        <set operator="and">
            <set operator="or">
                <prop key="operating_system" value="cpe:2.3:o:samsung:exynos_2200_firmware:-:*:*:*:*:*:*:*"/>
            </set>
            <set operator="or">
                <prop key="device" value="cpe:2.3:h:samsung:exynos_2200:-:*:*:*:*:*:*:*"/>
            </set>
        </set>
        <set operator="and">
            <set operator="or">
                <prop key="operating_system" value="cpe:2.3:o:samsung:exynos_modem_5123_firmware:-:*:*:*:*:*:*:*"/>
            </set>
            <set operator="or">
                <prop key="device" value="cpe:2.3:h:samsung:exynos_modem_5123:-:*:*:*:*:*:*:*"/>
            </set>
        </set>
        <set operator="and">
            <set operator="or">
                <prop key="operating_system" value="cpe:2.3:o:samsung:exynos_modem_5300_firmware:-:*:*:*:*:*:*:*"/>
            </set>
            <set operator="or">
                <prop key="device" value="cpe:2.3:h:samsung:exynos_modem_5300:-:*:*:*:*:*:*:*"/>
            </set>
        </set>
        <set operator="and">
            <set operator="or">
                <prop key="operating_system" value="cpe:2.3:o:samsung:exynos_auto_t5123_firmware:-:*:*:*:*:*:*:*"/>
            </set>
            <set operator="or">
                <prop key="device" value="cpe:2.3:h:samsung:exynos_auto_t5123:-:*:*:*:*:*:*:*"/>
            </set>
        </set>
    </set>
    <prop key="program_influence" value="input"/>
</set>