CVE-2024-28067: Medium severity samsung exynos modem 5300 firmware vulnerability
Published Jul 9, 2024
·Updated
A vulnerability in Samsung Exynos Modem 5300 allows a Man-in-the-Middle (MITM) attacker to downgrade the security mode of packets going to the victim, enabling the attacker to send messages to the victim in plaintext.
Affected Software
2 affected components
All of the following
Samsung Exynos Modem 5300 Firmware
Samsung Exynos Modem 5300
Event History
Jul 9, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via NVD·06:15 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-28067?
CVE-2024-28067 is categorized with a high severity due to its potential for a Man-in-the-Middle (MITM) attack.
2
How do I fix CVE-2024-28067?
Fixing CVE-2024-28067 involves updating the Samsung Exynos Modem 5300 firmware to the latest version provided by Samsung.
3
What type of attack is enabled by CVE-2024-28067?
CVE-2024-28067 allows a Man-in-the-Middle (MITM) attack that can downgrade security protocols.
4
Who is affected by CVE-2024-28067?
CVE-2024-28067 affects devices using the Samsung Exynos Modem 5300 firmware.
5
What can attackers do using CVE-2024-28067?
Attackers can exploit CVE-2024-28067 to send messages to victims in plaintext by manipulating packet security modes.