CVE-2021-25470: Code Injection
Published Oct 6, 2021
·Updated
An improper caller check logic of SMC call in TEEGRIS secure OS prior to SMR Oct-2021 Release 1 can be used to compromise TEE.
Affected Software
4 affected components
Google Android=9.0
Google Android=10.0
Google Android=11.0
Samsung Exynos
Event History
Oct 6, 2021
CVE Published
via MITRE·05:07 PM
Data Sourced
via MITRE·05:07 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-25470?
CVE-2021-25470 is a vulnerability in the TEEGRIS secure OS that allows an attacker to compromise TEE by exploiting an improper caller check logic of an SMC call.
2
What is the severity of CVE-2021-25470?
CVE-2021-25470 has a severity rating of 7.9, which is considered high.
3
Which versions of Google Android are affected by CVE-2021-25470?
Google Android versions 9.0, 10.0, and 11.0 are affected by CVE-2021-25470.
4
How can an attacker exploit CVE-2021-25470?
An attacker can exploit CVE-2021-25470 by taking advantage of the improper caller check logic of the SMC call in TEEGRIS secure OS prior to SMR Oct-2021 Release 1.
5
Is Samsung Exynos affected by CVE-2021-25470?
No, Samsung Exynos is not vulnerable to CVE-2021-25470.