CVE-2023-29089
Shannon Baseband Negative-Size Memcpy / Out-Of-Bounds Read
Severity Score
7.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos 9110, and Exynos Auto T5123. Memory corruption can occur due to insufficient parameter validation while decoding SIP multipart messages.
There is a negative-size memcpy (heap overflow) when decoding the body of SIP multipart messages. According to debug strings in the modem image, this functionality is implemented in IMSPL_SipFragDecode.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-03-31 CVE Reserved
- 2023-04-14 CVE Published
- 2024-08-02 CVE Updated
- 2024-09-24 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-125: Out-of-bounds Read
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/172292/Shannon-Baseband-Negative-Size-Memcpy-Out-Of-Bounds-Read.html |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://semiconductor.samsung.com/support/quality-support/product-security-updates | 2023-05-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Samsung Search vendor "Samsung" | Exynos 5300 Firmware Search vendor "Samsung" for product "Exynos 5300 Firmware" | - | - |
Affected
| in | Samsung Search vendor "Samsung" | Exynos 5300 Search vendor "Samsung" for product "Exynos 5300" | - | - |
Safe
|
Samsung Search vendor "Samsung" | Exynos 5123 Firmware Search vendor "Samsung" for product "Exynos 5123 Firmware" | - | - |
Affected
| in | Samsung Search vendor "Samsung" | Exynos 5123 Search vendor "Samsung" for product "Exynos 5123" | - | - |
Safe
|
Samsung Search vendor "Samsung" | Exynos 980 Firmware Search vendor "Samsung" for product "Exynos 980 Firmware" | - | - |
Affected
| in | Samsung Search vendor "Samsung" | Exynos 980 Search vendor "Samsung" for product "Exynos 980" | - | - |
Safe
|
Samsung Search vendor "Samsung" | Exynos 9110 Firmware Search vendor "Samsung" for product "Exynos 9110 Firmware" | - | - |
Affected
| in | Samsung Search vendor "Samsung" | Exynos 9110 Search vendor "Samsung" for product "Exynos 9110" | - | - |
Safe
|
Samsung Search vendor "Samsung" | Exynos 1080 Firmware Search vendor "Samsung" for product "Exynos 1080 Firmware" | - | - |
Affected
| in | Samsung Search vendor "Samsung" | Exynos 1080 Search vendor "Samsung" for product "Exynos 1080" | - | - |
Safe
|
Samsung Search vendor "Samsung" | Exynos Auto T5123 Firmware Search vendor "Samsung" for product "Exynos Auto T5123 Firmware" | - | - |
Affected
| in | Samsung Search vendor "Samsung" | Exynos Auto T5123 Search vendor "Samsung" for product "Exynos Auto T5123" | - | - |
Safe
|