CVE-2022-39901: Medium severity samsung exynos firmware vulnerability
Improper authentication in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to disable the network traffic encryption between UE and gNodeB.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-39901?
CVE-2022-39901 refers to an improper authentication vulnerability in Exynos baseband prior to SMR DEC-2022 Release 1, allowing a remote attacker to disable network traffic encryption between UE and gNodeB.
How severe is CVE-2022-39901?
CVE-2022-39901 has a severity rating of 6.5 which is considered medium.
What software is affected by CVE-2022-39901?
The Exynos baseband firmware is affected by CVE-2022-39901.
How can a remote attacker exploit CVE-2022-39901?
A remote attacker can exploit CVE-2022-39901 by disabling the network traffic encryption between UE and gNodeB.
Is Samsung Exynos vulnerable to CVE-2022-39901?
No, the Samsung Exynos itself is not vulnerable. Only the Exynos baseband firmware is affected.
How can I fix CVE-2022-39901?
To fix CVE-2022-39901, it is recommended to apply SMR DEC-2022 Release 1 or a subsequent security update provided by Samsung.
Where can I find more information about CVE-2022-39901?
You can find more information about CVE-2022-39901 on the Samsung Mobile Security website.