Samsung Mobile Devices Improper Input Validation Vulnerability (CVE-2021-25489)
Samsung mobile devices contain an improper input validation vulnerability within the modem interface driver that results in a format string bug leading to kernel panic.
A local attacker, with a low-privilege account, can achieve partial data exposure, partial service disruption. Federal agencies are required to remediate by 2023-07-20 under CISA BOD 22-01.
This is a Improper Input Validation (CWE-20) vulnerability in Samsung Mobile Devices. Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug leading to kernel panic. Exploitation requires local access, low attack complexity, a low-privilege authenticated account, and no user interaction required.
Probably yes if any of these apply:
CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2023-06-29 based on evidence of active exploitation in the wild. Federal agencies required to remediate by 2023-07-20.
Manual remediation steps
No tested PowerShell script for this entry yet. We’re prioritising automation based on user demand.