2024-07-09 20:03:11 +00:00
{
"id" : "CVE-2024-31957" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2024-07-09T18:15:10.013" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T09:14:12.443" ,
"vulnStatus" : "Modified" ,
2024-07-09 20:03:11 +00:00
"cveTags" : [ ] ,
"descriptions" : [
{
"lang" : "en" ,
"value" : "A vulnerability was discovered in Samsung Mobile Processors Exynos 2200 and Exynos 2400 where they lack a check for the validation of native handles, which can result in a DoS(Denial of Service) attack by unmapping an invalid length."
2024-07-12 16:03:11 +00:00
} ,
{
"lang" : "es" ,
"value" : "Se descubri\u00f3 una vulnerabilidad en los procesadores m\u00f3viles Samsung Exynos 2200 y Exynos 2400 donde carecen de una verificaci\u00f3n para la validaci\u00f3n de identificadores nativos, lo que puede resultar en un ataque DoS (denegaci\u00f3n de servicio) al desasignar una longitud no v\u00e1lida."
2024-07-09 20:03:11 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
2024-07-12 16:03:11 +00:00
{
2024-12-08 03:06:42 +00:00
"source" : "cve@mitre.org" ,
"type" : "Secondary" ,
2024-07-12 16:03:11 +00:00
"cvssData" : {
"version" : "3.1" ,
2024-12-08 03:06:42 +00:00
"vectorString" : "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" ,
"baseScore" : 6.2 ,
"baseSeverity" : "MEDIUM" ,
"attackVector" : "LOCAL" ,
2024-07-12 16:03:11 +00:00
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "HIGH"
2024-07-12 16:03:11 +00:00
} ,
2024-12-08 03:06:42 +00:00
"exploitabilityScore" : 2.5 ,
2024-07-12 16:03:11 +00:00
"impactScore" : 3.6
} ,
2024-07-09 20:03:11 +00:00
{
2024-12-08 03:06:42 +00:00
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
2024-07-09 20:03:11 +00:00
"cvssData" : {
"version" : "3.1" ,
2024-12-08 03:06:42 +00:00
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" ,
"baseScore" : 7.5 ,
"baseSeverity" : "HIGH" ,
"attackVector" : "NETWORK" ,
2024-07-09 20:03:11 +00:00
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "HIGH"
2024-07-09 20:03:11 +00:00
} ,
2024-12-08 03:06:42 +00:00
"exploitabilityScore" : 3.9 ,
2024-07-09 20:03:11 +00:00
"impactScore" : 3.6
}
]
} ,
2024-07-12 16:03:11 +00:00
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-1284"
}
]
}
] ,
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:samsung:exynos_2200_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "63C0D9AC-BD23-48C9-83E7-301DEC06E583"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:samsung:exynos_2200:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A72ADEBB-ED72-4A5B-BB27-95EDE43F8116"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:samsung:exynos_2400_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "16D9272E-1794-48FF-B6A4-8F48395BA38E"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:samsung:exynos_2400:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "932F5FB3-5527-44D7-9DD9-EF03963E3CA3"
}
]
}
]
}
] ,
2024-07-09 20:03:11 +00:00
"references" : [
{
"url" : "https://semiconductor.samsung.com/support/quality-support/product-security-updates/" ,
2024-07-12 16:03:11 +00:00
"source" : "cve@mitre.org" ,
"tags" : [
"Vendor Advisory"
]
2024-07-09 20:03:11 +00:00
} ,
{
"url" : "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-31957/" ,
2024-07-12 16:03:11 +00:00
"source" : "cve@mitre.org" ,
"tags" : [
"Vendor Advisory"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://semiconductor.samsung.com/support/quality-support/product-security-updates/" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-31957/" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
2024-07-09 20:03:11 +00:00
}
]
}