CVE-2024-28067

MEDIUM

Samsung Exynos Modem 5300 Firmware - Man-in-the-Middle Security Mode Downgrade

Title source: llm
STIX 2.1

Description

A vulnerability in Samsung Exynos Modem 5300 allows a Man-in-the-Middle (MITM) attacker to downgrade the security mode of packets going to the victim, enabling the attacker to send messages to the victim in plaintext.

Scores

CVSS v3 5.3
EPSS 0.0072
EPSS Percentile 72.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-295
Status published
Products (1)
samsung/exynos_modem_5300_firmware
Published Jul 09, 2024
Tracked Since Feb 18, 2026