← All CVEs

CVE-2021-25487

high · 7.3Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions or discontinue use of the product if updates are unavailable

Added 2023-06-29Remediation due 2023-07-20

Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dereference of invalid function pointer.

7.3
CVSS
0.6%
EPSS (exploit prob.)
49th
EPSS percentile
2021-10-06
Published

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

Weaknesses

CWE-125

Affected products

VendorProductAffected versions
samsungandroid8.1
samsungandroid9.0
samsungandroid9.0
samsungandroid9.0
samsungandroid9.0
samsungandroid9.0
samsungandroid9.0
samsungandroid9.0
samsungandroid9.0
samsungandroid9.0
samsungandroid10.0
samsungandroid10.0
samsungandroid10.0
samsungandroid10.0
samsungandroid10.0
samsungandroid10.0
samsungandroid10.0
samsungandroid10.0
samsungandroid10.0
samsungandroid11.0
samsungandroid11.0
samsungandroid11.0
samsungandroid11.0
samsungandroid11.0
samsungandroid11.0
samsungandroid11.0
samsungandroid11.0
samsungandroid11.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-25487