Impact
An incorrect handling of unauthenticated downlink RRC Setup messages within Samsung’s NR RRC implementation can cause the baseband processor to crash. This crash interrupts cellular communication, effectively denying service to the affected device. The flaw arises from a missing authentication check (CWE‑346).
Affected Systems
The vulnerability is known to affect Samsung’s Exynos 1080 firmware. The vendor’s description also references other processor families, but the CNA list explicitly states only the Exynos 1080 firmware as affected. Devices running firmware from that series without the official update are potentially vulnerable.
Risk and Exploitability
The CVSS score of 4.0 indicates moderate severity, and the EPSS is below 1%, meaning exploitation is considered unlikely at present. The flaw is not listed in the CISA KEV catalogue. The attack vector is inferred to be remote via the cellular network, where an adversary could transmit a crafted RRC Setup message to trigger the crash. No public exploitation has been reported, but the operational impact of a baseband crash is significant for carriers and end‑users.
OpenCVE Enrichment