CVE-2025-22377
Severity CVSS v4.0:
Pending analysis
Type:
CWE-787
Out-of-bounds Write
Publication date:
27/05/2025
Last modified:
25/06/2025
Description
An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. A Heap-based Out-of-Bounds Write exists in the GPRS protocol implementation because of a mismatch between the actual length of the payload and the length declared within the payload.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:samsung:exynos_1080_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:samsung:exynos_1080:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:samsung:exynos_1280_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:samsung:exynos_1280:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:samsung:exynos_1330_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:samsung:exynos_1330:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:samsung:exynos_1380_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:samsung:exynos_1380:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:samsung:exynos_1480_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:samsung:exynos_1480:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:samsung:exynos_2100_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:samsung:exynos_2100:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:samsung:exynos_2200_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:samsung:exynos_2200:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:samsung:exynos_2400_firmware:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page