Impact
An input validation failure in Samsung Exynos processors allows an attacker to exploit the lack of proper input checks, leading to a denial of service condition. This flaw is categorized as CWE‑20, which represents an unsafe handling of input that can compromise system availability without affecting data confidentiality or integrity.
Affected Systems
Affected units include a broad range of Samsung Exynos processors used in mobile, wearable, and modem devices. The models listed are Exynos 980, 850, 990, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 1680, 9110, W920, W930, W1000, and the modem variants 5123, 5300, 5400, 5410. No specific firmware or hardware version ranges are provided, so all current implementations of these chips should be considered at risk until a vendor patch is applied.
Risk and Exploitability
The vulnerability has a CVSS score of 7.5, indicating a high impact on availability, while the EPSS score is below 1%, suggesting currently low exploit probability. The issue is not listed in CISA’s KEV catalog, implying no confirmed public exploitation yet. Likely attack vectors involve supplying malformed data to the processor through device firmware or applications, though the exact exploitation path is not detailed in the description. Even in the absence of an active exploit, the potential for a silent DoS makes this a significant concern for any system relying on these processors.
OpenCVE Enrichment