CVE-2023-37367
Last modified
CVE-2023-37367 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem (Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. In the NAS Task, an improperly implemented security check for standard can disallow desired services for a while via consecutive NAS messages.. EPSS estimates a 0.44% chance of exploitation in the next 30 days.
Description
An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem (Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. In the NAS Task, an improperly implemented security check for standard can disallow desired services for a while via consecutive NAS messages.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Samsung | Exynos 9820 Firmware | All versions |
| Samsung | Exynos 980 Firmware | All versions |
| Samsung | Exynos 850 Firmware | All versions |
| Samsung | Exynos 1080 Firmware | All versions |
| Samsung | Exynos 2100 Firmware | All versions |
| Samsung | Exynos 2200 Firmware | All versions |
| Samsung | Exynos 1280 Firmware | All versions |
| Samsung | Exynos 1380 Firmware | All versions |
| Samsung | Exynos 1330 Firmware | All versions |
| Samsung | Exynos Modem 5123 Firmware | All versions |
| Samsung | Exynos Modem 5300 Firmware | All versions |
| Samsung | Exynos Auto T5123 Firmware | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-37367?
How severe is CVE-2023-37367?
How do I fix CVE-2023-37367?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-3736Inappropriate implementation in Custom Tabs in Google Chrome…4.3
- CVE-2023-37360pacparser_find_proxy in Pacparser before 1.4.2 allows JavaSc…6.1
- CVE-2023-37361REDCap 12.0.26 LTS and 12.3.2 Standard allows SQL Injection …2.7
- CVE-2023-37362Weintek Weincloud v0.13.6 could allow an attacker to abu…8.8
- CVE-2023-37364In WS-Inc J WBEM Server 4.7.4 before 4.7.5, the CIM-XML prot…9.1
- CVE-2023-37365Hnswlib 0.7.0 has a double free in init_index when the M arg…6.5
- CVE-2023-37368An issue was discovered in Samsung Exynos Mobile Processor, …7.5
- CVE-2023-37369In Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.…7.5
- CVE-2023-3737Inappropriate implementation in Notifications in Google Chro…4.3
- CVE-2023-37372A vulnerability has been identified in RUGGEDCOM CROSSBOW (A…9.8
- CVE-2023-37373A vulnerability has been identified in RUGGEDCOM CROSSBOW (A…7.5
- CVE-2023-37374A vulnerability has been identified in Tecnomatix Plant Simu…7.8
Are you affected by CVE-2023-37367?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
