Impact
This vulnerability allows an untrusted pointer to be dereferenced, permitting malicious manipulation of memory pointers. The flaw, classified as CWE-822, can lead to memory corruption that compromises data integrity or may be leveraged to modify program behavior. The CVSS score of 5.5 indicates medium severity, suggesting that while the impact is non‑trivial, it does not automatically grant remote code execution. Based on the description, it is inferred that exploitation requires supplying crafted pointer data, implying a local or privileged attack vector rather than a broad remote one.
Affected Systems
Samsung Open Source mTower is affected for all releases prior to the commit referenced as 102d3dc75cf8e58e68e4bea54ae3c803992c91be. Versions after this commit are considered safe. The product is the open‑source monitoring framework developed by Samsung, and no specific version numbers beyond the commit identifier are listed.
Risk and Exploitability
The medium CVSS score reflects a moderate risk that an attacker with sufficient access could corrupt memory and disrupt normal operation. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog, indicating that large‑scale exploitation has not been reported. Likely attack conditions would involve an attacker having access to untrusted input that can influence pointer values used by mTower, such as by submitting malformed data or exploiting an insecure configuration. The lack of a documented attack path reduces the immediacy of the threat, but the potential for memory corruption warrants prompt remediation.
OpenCVE Enrichment