CVE-2024-39343

HIGH

Samsung Exynos 2100 Firmware - Denial of Service

Title source: rule
STIX 2.1

Description

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, Modem 5123, and Modem 5300. The baseband software does not properly check the length specified by the MM (Mobility Management) module, which can lead to Denial of Service.

Scores

CVSS v3 7.0
EPSS 0.0108
EPSS Percentile 77.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1284
Status published
Products (9)
samsung/exynos_1280_firmware
samsung/exynos_1330_firmware
samsung/exynos_1380_firmware
samsung/exynos_1480_firmware
samsung/exynos_2100_firmware
samsung/exynos_2400_firmware
samsung/exynos_9110_firmware
samsung/exynos_modem_5123_firmware
samsung/exynos_modem_5300_firmware
Published Dec 02, 2024
Tracked Since Feb 18, 2026