First published: Fri Feb 11 2022(Updated: )
Improper input validation in Exynos baseband prior to SMR Feb-2022 Release 1 allows attackers to send arbitrary NAS signaling messages with fake base station.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =10.0 | |
Google Android | =11.0 | |
Google Android | =12.0 | |
Samsung Exynos |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23425 is an improper input validation vulnerability in Exynos baseband prior to SMR Feb-2022 Release 1, allowing attackers to send arbitrary NAS signaling messages with fake base station.
Google Android versions 10.0, 11.0, and 12.0 are affected by CVE-2022-23425.
The severity of CVE-2022-23425 is critical with a CVSS score of 9.8.
To fix CVE-2022-23425, users should apply the SMR Feb-2022 Release 1 security update provided by Samsung or follow the instructions from their device manufacturer.
The Common Weakness Enumeration (CWE) ID for CVE-2022-23425 is CWE-20.