CVE-2024-39343
Last modified
CVE-2024-39343 is a high-severity vulnerability rated 7/10 on the CVSS scale. An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, Modem 5123, and Modem 5300. The baseband software does not properly check the length specified by the MM (Mobility Management) module, which can lead to Denial of Service.. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, Modem 5123, and Modem 5300. The baseband software does not properly check the length specified by the MM (Mobility Management) module, which can lead to Denial of Service.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Samsung | Exynos 2100 Firmware | All versions |
| Samsung | Exynos 1280 Firmware | All versions |
| Samsung | Exynos 1330 Firmware | All versions |
| Samsung | Exynos 1380 Firmware | All versions |
| Samsung | Exynos 1480 Firmware | All versions |
| Samsung | Exynos 2400 Firmware | All versions |
| Samsung | Exynos 9110 Firmware | All versions |
| Samsung | Exynos Modem 5123 Firmware | All versions |
| Samsung | Exynos Modem 5300 Firmware | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-39343?
How severe is CVE-2024-39343?
How do I fix CVE-2024-39343?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-39338axios 1.7.2 allows SSRF via unexpected behavior where reques…7.5
- CVE-2024-39339A vulnerability has been discovered in all versions of Smart…7.5
- CVE-2024-3934The Mercado Pago payments for WooCommerce plugin for WordPre…6.5
- CVE-2024-39340The authentication system of Securepoint UTM mishandles OTP …8.8
- CVE-2024-39341Entrust Instant Financial Issuance (On Premise) Software (fo…5.9
- CVE-2024-39342Entrust Instant Financial Issuance (formerly known as Cardwi…6.6
- CVE-2024-39344An issue was discovered in the Docusign API package 8.142.14…8.1
- CVE-2024-39345AdTran 834-5 HDC17600021F1 (SmartOS 11.1.1.1) devices enable…7.2
- CVE-2024-39347Incorrect default permissions vulnerability in firewall func…5.9
- CVE-2024-39348Download of code without integrity check vulnerability in Ai…7.5
- CVE-2024-39349A vulnerability regarding buffer copy without checking size …9.8
- CVE-2024-3935In Eclipse Mosquito, versions from 2.0.0 through 2.0.18, if …6.5
Are you affected by CVE-2024-39343?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
