CVE-2016-11050

MEDIUM

Samsung mobile devices - Code Injection

Title source: llm
STIX 2.1

Description

An issue was discovered on Samsung mobile devices with S3(KK), Note2(KK), S4(L), Note3(L), and S5(L) software. An attacker can rewrite the IMEI by flashing crafted firmware. The Samsung ID is SVE-2016-5562 (March 2016).

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://security.samsungmobile.com/securityUpdate.smsb

Scores

CVSS v3 4.3
EPSS 0.0007
EPSS Percentile 20.4%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Details

Status published
Products (5)
samsung/note2_firmware
samsung/note3_firmware
samsung/s3_firmware
samsung/s4_firmware
samsung/s5_firmware
Published Apr 07, 2020
Tracked Since Feb 18, 2026