A vulnerability was discovered in Samsung Mobile Processors Exynos 1280, Exynos 2200, Exynos 1330, Exynos 1380, and Exynos 2400 where they do not properly check the length of the data, which can lead to a Information disclosure.
References
Link | Resource |
---|---|
https://semiconductor.samsung.com/support/quality-support/product-security-updates/ | Vendor Advisory |
https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-27362/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
History
12 Jul 2024, 14:58
Type | Values Removed | Values Added |
---|---|---|
First Time |
Samsung
Samsung exynos 1380 Samsung exynos 1330 Firmware Samsung exynos 1330 Samsung exynos 1280 Samsung exynos 1380 Firmware Samsung exynos 1280 Firmware Samsung exynos 2400 Samsung exynos 2400 Firmware Samsung exynos 2200 Samsung exynos 2200 Firmware |
|
CWE | CWE-1284 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
Summary |
|
|
References | () https://semiconductor.samsung.com/support/quality-support/product-security-updates/ - Vendor Advisory | |
References | () https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-27362/ - Vendor Advisory | |
CPE | cpe:2.3:o:samsung:exynos_1380_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:samsung:exynos_2400:-:*:*:*:*:*:*:* cpe:2.3:o:samsung:exynos_2200_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:samsung:exynos_1280:-:*:*:*:*:*:*:* cpe:2.3:h:samsung:exynos_1330:-:*:*:*:*:*:*:* cpe:2.3:o:samsung:exynos_1330_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:samsung:exynos_1380:-:*:*:*:*:*:*:* cpe:2.3:h:samsung:exynos_2200:-:*:*:*:*:*:*:* cpe:2.3:o:samsung:exynos_2400_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:samsung:exynos_1280_firmware:-:*:*:*:*:*:*:* |
09 Jul 2024, 18:18
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-09 18:15
Updated : 2024-07-12 14:58
NVD link : CVE-2024-27362
Mitre link : CVE-2024-27362
CVE.ORG link : CVE-2024-27362
JSON object : View
Products Affected
samsung
- exynos_2200_firmware
- exynos_1380
- exynos_1330_firmware
- exynos_2200
- exynos_1330
- exynos_2400_firmware
- exynos_2400
- exynos_1380_firmware
- exynos_1280
- exynos_1280_firmware
CWE
CWE-1284
Improper Validation of Specified Quantity in Input