CVE-2021-25500: Input Validation
Published Nov 5, 2021
·Updated
A missing input validation in HDCP LDFW prior to SMR Nov-2021 Release 1 allows attackers to overwrite TZASC allowing TEE compromise.
Affected Software
6 affected components
Google Android=10.0
Google Android=11.0
Samsung Exynos 2100
Samsung Exynos 980
Samsung Exynos 9820
Samsung Exynos 9830
Event History
Nov 5, 2021
CVE Published
via MITRE·02:03 AM
Data Sourced
via MITRE·02:03 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
CVE-2021-25500
2
What is the severity of CVE-2021-25500?
The severity of CVE-2021-25500 is high (4.4).
3
Which software versions are affected by CVE-2021-25500?
Google Android 10.0 and 11.0 are affected by CVE-2021-25500.
4
How can attackers exploit CVE-2021-25500?
Attackers can exploit CVE-2021-25500 to overwrite TZASC, allowing TEE compromise.
5
Is Samsung Exynos 2100 vulnerable to CVE-2021-25500?
No, Samsung Exynos 2100 is not vulnerable to CVE-2021-25500.