CVE-2023-21467: Critical severity Samsung Exynos Baseband vulnerability
Published Sep 3, 2025
·Updated
Error in 3GPP specification implementation in Exynos baseband prior to SMR Apr-2023 Release 1 allows incorrect handling of unencrypted message.
Affected Software
2 affected components
Samsung Exynos Baseband<SMR Apr-2023 Release 1
Samsung Exynos
Event History
Sep 3, 2025
CVE Published
via MITRE·05:16 AM
Data Sourced
via MITRE·05:16 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-21467?
CVE-2023-21467 has a high severity due to the potential for incorrect handling of unencrypted messages in the Exynos baseband.
2
How do I fix CVE-2023-21467?
To fix CVE-2023-21467, update the Samsung Exynos Baseband software to the SMR Apr-2023 Release 1 or later.
3
What software is affected by CVE-2023-21467?
CVE-2023-21467 affects the Samsung Exynos Baseband versions prior to SMR Apr-2023 Release 1.
4
What type of vulnerability is CVE-2023-21467?
CVE-2023-21467 is categorized as an implementation error in the 3GPP specification within the Exynos baseband.
5
Are there any public exploitations of CVE-2023-21467?
As of now, there are no confirmed public exploitations reported for CVE-2023-21467.