Description
An improper input validation in UEFI Firmware prior to Firmware update Oct-2023 Release in Galaxy Book, Galaxy Book Pro, Galaxy Book Pro 360 and Galaxy Book Odyssey allows local attacker to execute SMM memory corruption.
Published: 2023-10-04
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-35102 An improper input validation in UEFI Firmware prior to Firmware update Oct-2023 Release in Galaxy Book, Galaxy Book Pro, Galaxy Book Pro 360 and Galaxy Book Odyssey allows local attacker to execute SMM memory corruption.
History

Thu, 19 Sep 2024 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Samsung Galaxy Book Galaxy Book Firmware Galaxy Book Odyssey Galaxy Book Odyssey Firmware Galaxy Book Pro Galaxy Book Pro 360 Galaxy Book Pro 360 Firmware Galaxy Book Pro Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: Samsung Mobile

Published:

Updated: 2024-09-19T19:25:14.770Z

Reserved: 2023-04-14T01:59:51.141Z

Link: CVE-2023-30738

cve-icon Vulnrichment

Updated: 2024-08-02T14:37:14.909Z

cve-icon NVD

Status : Modified

Published: 2023-10-04T04:15:13.733

Modified: 2024-11-21T08:00:48.307

Link: CVE-2023-30738

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses