CVE-2023-21501: Input Validation
Published May 4, 2023
·Updated
Improper input validation vulnerability in mPOS fiserve trustlet prior to SMR May-2023 Release 1 allows local attackers to execute arbitrary code.
Affected Software
8 affected components
Samsung android=13.0
Samsung android=13.0-smr-apr-2023-r1
Samsung android=13.0-smr-dec-2022-r1
Samsung android=13.0-smr-feb-2023-r1
Samsung android=13.0-smr-jan-2023-r1
Samsung android=13.0-smr-mar-2023-r1
Samsung android=13.0-smr-nov-2022-r1
Samsung android=13.0-smr-oct-2022-r1
Event History
May 4, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
09:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-21501?
CVE-2023-21501 has a high severity due to the potential for local attackers to execute arbitrary code.
2
How do I fix CVE-2023-21501?
To fix CVE-2023-21501, users should update their Samsung Android devices to the latest SMR May-2023 Release 1.
3
Which versions of Samsung Android are affected by CVE-2023-21501?
CVE-2023-21501 affects Samsung Android versions prior to 13.0 SMR May-2023 Release 1.
4
Who can exploit CVE-2023-21501?
CVE-2023-21501 can be exploited by local attackers with access to the affected device.
5
What type of vulnerability is CVE-2023-21501?
CVE-2023-21501 is categorized as an improper input validation vulnerability.