CVE-2022-28793
Last modified
CVE-2022-28793 is a medium-severity vulnerability rated 4.4/10 on the CVSS scale. Given the TEE is compromised and controlled by the attacker, improper state maintenance in StrongBox allows attackers to change Android ROT during device boot cycle after compromising TEE. The patch is applied in Galaxy S22 to prevent change of Android ROT after first initialization at boot time.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
Given the TEE is compromised and controlled by the attacker, improper state maintenance in StrongBox allows attackers to change Android ROT during device boot cycle after compromising TEE. The patch is applied in Galaxy S22 to prevent change of Android ROT after first initialization at boot time.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Samsung | Galaxy S22 Firmware | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-28793?
How severe is CVE-2022-28793?
How do I fix CVE-2022-28793?
Are you affected by CVE-2022-28793?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
