CVE-2022-28793

MEDIUM

Samsung Galaxy S22 Firmware - Improper State Maintenance in StrongBox

Title source: llm
STIX 2.1

Description

Given the TEE is compromised and controlled by the attacker, improper state maintenance in StrongBox allows attackers to change Android ROT during device boot cycle after compromising TEE. The patch is applied in Galaxy S22 to prevent change of Android ROT after first initialization at boot time.

References (1)

Core 1
Core References

Scores

CVSS v3 4.4
EPSS 0.0006
EPSS Percentile 19.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-754
Status published
Products (1)
samsung/galaxy_s22_firmware
Published May 03, 2022
Tracked Since Feb 18, 2026