CVE-2022-39830: High severity samsung mtower vulnerability
Published Sep 5, 2022
·Updated
signpFwInfo in Samsung mTower through 0.3.0 has a missing check on the return value of ECKEYsetpublickeyaffinecoordinates, leading to a denial of service.
Affected Software
1 affected component
samsung mTower<=0.3.0
Event History
Sep 5, 2022
CVE Published
via MITRE·03:43 AM
Data Sourced
via MITRE·03:43 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-39830?
CVE-2022-39830 has a medium severity level as it leads to a denial of service due to a vulnerability in Samsung mTower.
2
How do I fix CVE-2022-39830?
To fix CVE-2022-39830, upgrade Samsung mTower to a version higher than 0.3.0 where the vulnerability has been addressed.
3
What causes the vulnerability in CVE-2022-39830?
The vulnerability in CVE-2022-39830 is caused by a missing check on the return value of the EC_KEY_set_public_key_affine_coordinates function.
4
Which versions of Samsung mTower are affected by CVE-2022-39830?
Samsung mTower versions up to and including 0.3.0 are affected by CVE-2022-39830.
5
What is the impact of CVE-2022-39830 on users?
The impact of CVE-2022-39830 on users is a potential denial of service, disrupting the functionality of affected applications.