CVE-2023-24033: Input Validation
The Samsung Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T512 baseband modem chipsets do not properly check format types specified by the Session Description Protocol (SDP) module, which can lead to a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-24033?
CVE-2023-24033 refers to a vulnerability in the Samsung Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T512 baseband modem chipsets, where they do not properly check format types specified by the Session Description Protocol (SDP) module, leading to a denial of service.
Which Samsung products are affected by CVE-2023-24033?
Samsung Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T512
What is the severity of CVE-2023-24033?
CVE-2023-24033 has a severity rating of 9.8 (Critical).
How can the CVE-2023-24033 vulnerability be exploited?
The vulnerability can be exploited by sending specially crafted format types through the Session Description Protocol (SDP), which can result in a denial of service.
Are there any references available for CVE-2023-24033?
Yes, you can find more information about CVE-2023-24033 at the following references: http://packetstormsecurity.com/files/172137/Shannon-Baseband-accept-type-SDP-Attribute-Memory-Corruption.html, https://semiconductor.samsung.com/processor/modem/, https://semiconductor.samsung.com/support/quality-support/product-security-updates/