CVE-2024-39890

EUVD-2024-38340
An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300. The baseband software does not properly check the length specified by the CC (Call Control). This can lead to an Out-of-Bounds write.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AC:H/AV:N/A:H/C:H/I:H/PR:N/S:U/UI:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 74%
Affected Products (NVD)
VendorProductVersion
samsungexynos_modem_5123_firmware
-
samsungexynos_modem_5300_firmware
-
samsungexynos_9820_firmware
-
samsungexynos_9825_firmware
-
samsungexynos_980_firmware
-
samsungexynos_990_firmware
-
samsungexynos_850_firmware
-
samsungexynos_1080_firmware
-
samsungexynos_2100_firmware
-
samsungexynos_1280_firmware
-
samsungexynos_2200_firmware
-
samsungexynos_1330_firmware
-
samsungexynos_1380_firmware
-
samsungexynos_1480_firmware
-
samsungexynos_2400_firmware
-
samsungexynos_9110_firmware
-
samsungexynos_w920_firmware
-
samsungexynos_w930_firmware
-
samsungexynos_w1000_firmware
-
𝑥
= Vulnerable software versions