First published: Thu Jan 04 2018(Updated: )
On Samsung mobile devices with N(7.x) software and Exynos chipsets, attackers can conduct a Trustlet stack overflow attack for arbitrary TEE code execution, in conjunction with a brute-force attack to discover unlock information (PIN, password, or pattern). The Samsung ID is SVE-2017-10733.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Mobile | =7.0 | |
Samsung Mobile | =7.1 | |
Samsung Mobile | =7.1.1 | |
Samsung Mobile | =7.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-5210 has a medium severity rating due to its potential to allow arbitrary TEE code execution.
To fix CVE-2018-5210, ensure that your Samsung mobile device is updated to the latest software version provided by Samsung.
CVE-2018-5210 affects Samsung mobile devices running N(7.x) software versions 7.0, 7.1, 7.1.1, and 7.1.2 on Exynos chipsets.
No, CVE-2018-5210 requires physical access to the device to exploit the vulnerability.
Exploitation of CVE-2018-5210 could lead to unauthorized access to sensitive information and compromise the integrity of the device's trusted execution environment.