First published: Fri Dec 18 2020(Updated: )
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. They allow attackers to conduct RPMB state-change attacks because an unauthorized RPMB write operation can be replayed, a related issue to CVE-2020-13799. The Samsung ID is SVE-2020-18100 (December 2020).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =8.0 | |
Google Android | =8.1 | |
Google Android | =9.0 | |
Google Android | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35551 has been classified with a medium severity level due to its potential to allow unauthorized RPMB write operations.
To mitigate CVE-2020-35551, users should update to the latest software version provided by Samsung that addresses this vulnerability.
CVE-2020-35551 affects Samsung mobile devices running Android versions 8.0, 8.1, 9.0, and 10.0 with Exynos chipsets.
CVE-2020-35551 allows attackers to conduct RPMB state-change attacks through unauthorized write operations.
Yes, CVE-2020-35551 is related to CVE-2020-13799, as it involves similar unauthorized replay of RPMB write operations.