Inclusion of sensitive information in log files in Samsung Mobile Firmware - CVE-2023-21492

 

Inclusion of sensitive information in log files in Samsung Mobile Firmware - CVE-2023-21492

Published: May 26, 2023


Vulnerability identifier: #VU76542
CSH Severity: Medium
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-21492
CWE-ID: CWE-532
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to kernel pointers are printed into the log file. A local application can read the log file and use the kernel pointers to bypass ASLR protection.

Note, the vulnerability is being exploited in the wild.


Affected software

Samsung Mobile Firmware

How to mitigate CVE-2023-21492

Install updates from vendor's website.

Samsung Mobile Firmware - update to SMR-MAY-2023

External References

Related Security Bulletins