Impact
A NULL pointer dereference in Samsung Open Source mTower can cause the software to crash unexpectedly. The flaw, catalogued as CWE-476, arises when the system allows unsafe pointer manipulation, leading to an unvalidated dereference. While the official description does not claim remote code execution, the crash can disrupt service availability and potentially expose the system to further attacks if critical components fail. The primary consequence is a denial of service, with insufficient evidence of confidentiality or integrity compromise.
Affected Systems
Samsung Open Source mTower is affected. The vulnerability exists in any build before the Git revision afef59aa6f55c5d5ebf9b14bc020bf1c2c37489a. No other versions or products are listed as impacted.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity vulnerability. EPSS is not available, so current exploit probability is unknown. The vulnerability is not present in CISA's KEV catalog. The attack vector is not explicitly defined in the advisory, but because the flaw requires manipulation of a pointer, it is inferred to be exploitable by local users with sufficient influence over the input to the mTower code. No prerequisites such as network access or elevated privileges are mentioned, so the risk is likely limited to contexts where the attacker has some degree of local interaction with the affected component.
OpenCVE Enrichment