CVE-2024-31956

An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks proper buffer length checking, which can result in an Out-of-Bounds Write.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:samsung:exynos_2200_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:samsung:exynos_2200:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:samsung:exynos_1480_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:samsung:exynos_1480:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:samsung:exynos_2400_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:samsung:exynos_2400:-:*:*:*:*:*:*:*

History

21 Nov 2024, 09:14

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.8
v2 : unknown
v3 : 8.4
References () https://semiconductor.samsung.com/support/quality-support/product-security-updates/ - Vendor Advisory () https://semiconductor.samsung.com/support/quality-support/product-security-updates/ - Vendor Advisory

16 Jul 2024, 16:27

Type Values Removed Values Added
First Time Samsung exynos 2400 Firmware
Samsung exynos 1480 Firmware
Samsung exynos 1480
Samsung exynos 2400
Samsung exynos 2200
Samsung exynos 2200 Firmware
Samsung
CPE cpe:2.3:o:samsung:exynos_2200_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:samsung:exynos_1480:-:*:*:*:*:*:*:*
cpe:2.3:o:samsung:exynos_2400_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:samsung:exynos_1480_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:samsung:exynos_2200:-:*:*:*:*:*:*:*
cpe:2.3:h:samsung:exynos_2400:-:*:*:*:*:*:*:*
CWE CWE-787
References () https://semiconductor.samsung.com/support/quality-support/product-security-updates/ - () https://semiconductor.samsung.com/support/quality-support/product-security-updates/ - Vendor Advisory
CVSS v2 : unknown
v3 : 8.4
v2 : unknown
v3 : 7.8
Summary
  • (es) Se descubrió un problema en el procesador móvil Samsung Exynos 2200, Exynos 1480, Exynos 2400. Carece de una verificación adecuada de la longitud del búfer, lo que puede resultar en una escritura fuera de los límites.

13 Jun 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-13 17:15

Updated : 2025-03-14 17:15


NVD link : CVE-2024-31956

Mitre link : CVE-2024-31956

CVE.ORG link : CVE-2024-31956


JSON object : View

Products Affected

samsung

  • exynos_1480_firmware
  • exynos_2400_firmware
  • exynos_2200
  • exynos_1480
  • exynos_2200_firmware
  • exynos_2400
CWE
CWE-787

Out-of-bounds Write