Impact
This vulnerability is an untrusted pointer dereference in Samsung Open Source mTower that permits pointer manipulation. If an attacker can influence the data that the software will dereference, the program may access memory that it should not, potentially corrupting memory or enabling the execution of arbitrary code. The weakness is classified as CWE-822 and could compromise confidentiality, integrity, or availability depending on the context in which mTower runs.
Affected Systems
Samsung Open Source mTower versions before commit 06994e303637512e39062f3e037c222e8448e57e are affected. The vulnerable code resides in the mTower repository and was patched in the referenced pull request.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that no widespread exploits are documented. Without an attack vector explicitly stated in the advisory, it is inferred that the flaw likely requires interaction with the mTower service or API, possibly exposing the risk to users who have authorized access or to processes that invoke mTower locally.
OpenCVE Enrichment