CVE-2023-37367

MEDIUM

Samsung Exynos Mobile Processor, Automotive Processor, and Modem - Denial of Service via NAS Task Security Check Bypass

Title source: llm
STIX 2.1

Description

An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem (Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. In the NAS Task, an improperly implemented security check for standard can disallow desired services for a while via consecutive NAS messages.

References (1)

Core 1

Scores

CVSS v3 5.3
EPSS 0.0005
EPSS Percentile 14.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (12)
samsung/exynos_1080_firmware
samsung/exynos_1280_firmware
samsung/exynos_1330_firmware
samsung/exynos_1380_firmware
samsung/exynos_2100_firmware
samsung/exynos_2200_firmware
samsung/exynos_850_firmware
samsung/exynos_980_firmware
samsung/exynos_9820_firmware
samsung/exynos_auto_t5123_firmware
... and 2 more
Published Sep 08, 2023
Tracked Since Feb 18, 2026