CVE-2023-21499: High severity samsung android vulnerability
Published May 4, 2023
·Updated
Out-of-bounds write vulnerability in TACommunicationmposencryptpin in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to execute arbitrary code.
Affected Software
8 affected components
Samsung android=13.0
Samsung android=13.0-smr-apr-2023-r1
Samsung android=13.0-smr-dec-2022-r1
Samsung android=13.0-smr-feb-2023-r1
Samsung android=13.0-smr-jan-2023-r1
Samsung android=13.0-smr-mar-2023-r1
Samsung android=13.0-smr-nov-2022-r1
Samsung android=13.0-smr-oct-2022-r1
Event History
May 4, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
09:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-21499?
CVE-2023-21499 is rated as a high-severity out-of-bounds write vulnerability.
2
How do I fix CVE-2023-21499?
To fix CVE-2023-21499, you should update your Samsung device to the latest security patch from May 2023 or later.
3
Which devices are affected by CVE-2023-21499?
CVE-2023-21499 affects Samsung Android 13.0 devices prior to the SMR May-2023 Release 1.
4
What type of attack can exploit CVE-2023-21499?
CVE-2023-21499 can be exploited by local attackers to execute arbitrary code on affected devices.
5
Is CVE-2023-21499 a network or local vulnerability?
CVE-2023-21499 is a local vulnerability that requires physical access to the device to exploit.