CVE-2022-39902: High severity samsung exynos firmware vulnerability
Published Dec 8, 2022
·Updated
Improper authorization in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to get sensitive information including IMEI via emergency call.
Affected Software
2 affected components
Samsung Exynos Firmware
Samsung Exynos
Event History
Dec 8, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-39902?
CVE-2022-39902 is an improper authorization vulnerability in Samsung Exynos baseband prior to SMR DEC-2022 Release 1.
2
What is the severity of CVE-2022-39902?
CVE-2022-39902 has a severity rating of 7.5 (High).
3
How does CVE-2022-39902 work?
CVE-2022-39902 allows a remote attacker to obtain sensitive information, including IMEI, via an emergency call.
4
Which software is affected by CVE-2022-39902?
CVE-2022-39902 affects Samsung Exynos Firmware.
5
How can I mitigate CVE-2022-39902?
To mitigate CVE-2022-39902, update to SMR DEC-2022 Release 1 or later as recommended by Samsung.