CVE-2017-18020

On Samsung mobile devices with L(5.x), M(6.x), and N(7.x) software and Exynos chipsets, attackers can execute arbitrary code in the bootloader because S Boot omits a size check during a copy of ramfs data to memory. The Samsung ID is SVE-2017-10598.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.4 HIGH
LOCAL
LOW
NONE
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 16%
VendorProductVersion
samsungsamsung_mobile
5.0
samsungsamsung_mobile
5.1
samsungsamsung_mobile
5.1.1
samsungsamsung_mobile
6.0
samsungsamsung_mobile
6.0.1
samsungsamsung_mobile
7.0
samsungsamsung_mobile
7.1
samsungsamsung_mobile
7.1.1
samsungsamsung_mobile
7.1.2
𝑥
= Vulnerable software versions