First published: Fri Apr 10 2020(Updated: )
An issue was discovered on Samsung mobile devices with software through 2015-11-12, affecting the Galaxy S6/S6 Edge, Galaxy S6 Edge+, and Galaxy Note5 with the Shannon333 chipset. There is a stack-based buffer overflow in the baseband process that is exploitable for remote code execution via a fake base station. The Samsung ID is SVE-2015-5123 (December 2015).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | ||
Samsung Galaxy Note5 | ||
Samsung Galaxy S6 | ||
Samsung Galaxy S6 Edge | ||
Samsung Galaxy S6 Edge\+ |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2015-8546 is critical with a score of 9.8.
Samsung mobile devices with software through 2015-11-12, including the Galaxy S6/S6 Edge, Galaxy S6 Edge+, and Galaxy Note5 with the Shannon333 chipset, are affected by CVE-2015-8546.
CVE-2015-8546 does not directly impact Google Android, but it affects Samsung mobile devices running on the Android operating system with the specified software version.
Yes, CVE-2015-8546 is exploitable for remote code execution.
To fix CVE-2015-8546, it is recommended to apply the security update provided by Samsung using the reference link.