Vulnerabilities
Vulnerable Software
Samsung:  >> Mtower  >> 0.3.0  Security Vulnerabilities
Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEE_GetObjectInfo1.
CVSS Score
7.5
EPSS Score
0.001
Published
2022-09-01
TEE_Malloc in Samsung mTower through 0.3.0 allows a trusted application to achieve Excessive Memory Allocation via a large len value, as demonstrated by a Numaker-PFM-M2351 TEE kernel crash.
CVSS Score
7.5
EPSS Score
0.001
Published
2022-08-11
The TEE_PopulateTransientObject and __utee_from_attr functions in Samsung mTower 0.3.0 allow a trusted application to trigger a memory overwrite, denial of service, and information disclosure by invoking the function TEE_PopulateTransientObject with a large number in the parameter attrCount.
CVSS Score
7.8
EPSS Score
0.0
Published
2022-08-04


Contact Us

Shodan ® - All rights reserved