CVE-2025-54329

EUVD-2025-37857
An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. The function used to send a multiple-payloads message (including an SMS message) lacks bounds checking, which can lead to a heap overflow.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA-ADPADP
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 20%
Affected Products (NVD)
VendorProductVersion
samsungexynos_1280_firmware
-
samsungexynos_1330_firmware
-
samsungexynos_1380_firmware
-
samsungexynos_1480_firmware
-
samsungexynos_1580_firmware
-
samsungexynos_2100_firmware
-
samsungexynos_2200_firmware
-
samsungexynos_2400_firmware
-
samsungexynos_2500_firmware
-
samsungexynos_850_firmware
-
samsungexynos_980_firmware
-
samsungexynos_990_firmware
-
samsungexynos_w930_firmware
-
samsungexynos_w920_firmware
-
samsungexynos_w1000_firmware
-
samsungmodem_5123_firmware
-
samsungmodem_5300_firmware
-
samsungmodem_5400_firmware
-
𝑥
= Vulnerable software versions