Impact
An issue in the MM component of Samsung Mobile Processor, Wearable Processor, and Modem units causes a Denial of Service when the device processes a 5G NR NAS registration accept message. The vulnerability stems from improper handling of that message, resulting in service interruption without exposing sensitive data or enabling code execution.
Affected Systems
The flaw affects Samsung Mobile Processor, Wearable Processor, and Modem solutions across a wide range of product lines, including Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, W920, W930, W1000, and Modems 5123, 5300. All devices using these processors and modems are potentially impacted; specific revision or configuration details are not disclosed.
Risk and Exploitability
The EPSS score is <1%, and the CVSS score is 7.5, indicating a high severity vulnerability that is currently unlikely to be publicly exploited. The vulnerability is not listed in the CISA KEV catalog, supporting the premise that no public exploitation has yet been observed. The attack vector is inferred to be via 5G network communication; an attacker able to send specially crafted NAS registration accept messages over a 5G NR link could trigger the DoS. The risk is primarily availability loss, while confidentiality and integrity remain unaffected.
OpenCVE Enrichment