CVE-2023-37377

LOW

Samsung Exynos 980 Firmware - Out-of-Bounds Read

Title source: rule
STIX 2.1

Description

An issue was discovered in Samsung Exynos Mobile Processor and Wearable Processor (Exynos 980, Exynos 850, Exynos 2100, and Exynos W920). Improper handling of length parameter inconsistency can cause incorrect packet filtering.

References (1)

Core 1

Scores

CVSS v3 2.0
EPSS 0.0004
EPSS Percentile 11.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-125
Status published
Products (4)
samsung/exynos_2100_firmware
samsung/exynos_850_firmware
samsung/exynos_980_firmware
samsung/exynos_w920_firmware
Published Sep 08, 2023
Tracked Since Feb 18, 2026