← All CVEs

CVE-2021-25489

low · 3.3Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions or discontinue use of the product if updates are unavailable

Added 2023-06-29Remediation due 2023-07-20

Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug leading to kernel panic.

3.3
CVSS
0.5%
EPSS (exploit prob.)
44th
EPSS percentile
2021-10-06
Published

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Weaknesses

CWE-20CWE-134

Affected products

VendorProductAffected versions
samsungandroid8.1
samsungandroid9.0
samsungandroid9.0
samsungandroid9.0
samsungandroid9.0
samsungandroid9.0
samsungandroid9.0
samsungandroid9.0
samsungandroid9.0
samsungandroid9.0
samsungandroid10.0
samsungandroid10.0
samsungandroid10.0
samsungandroid10.0
samsungandroid10.0
samsungandroid10.0
samsungandroid10.0
samsungandroid10.0
samsungandroid10.0
samsungandroid11.0
samsungandroid11.0
samsungandroid11.0
samsungandroid11.0
samsungandroid11.0
samsungandroid11.0
samsungandroid11.0
samsungandroid11.0
samsungandroid11.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-25489