CVE-2024-31955

MEDIUM

Samsung eMMC KLMAG2GE4A and KLM8G1WEMB - Improper Certificate Validation via Electromagnetic Fault Injection

Title source: llm
STIX 2.1

Description

An issue was discovered in Samsung eMMC with KLMAG2GE4A and KLM8G1WEMB firmware. Code bypass through Electromagnetic Fault Injection allows an attacker to successfully authenticate and write to the RPMB (Replay Protected Memory Block) area without possessing secret information.

References (1)

Core 1

Scores

CVSS v3 4.9
EPSS 0.0023
EPSS Percentile 14.0%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-295
Status published
Published Oct 15, 2024
Tracked Since Feb 18, 2026