CVE-2023-31114

An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300. Incorrect resource transfer between spheres can cause unintended querying of the SIM status via a crafted application.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:samsung:exynos_5123_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:samsung:exynos_5123:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:samsung:exynos_5300_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:samsung:exynos_5300:-:*:*:*:*:*:*:*

History

14 Jun 2023, 13:43

Type Values Removed Values Added
References (MISC) https://semiconductor.samsung.com/support/quality-support/product-security-updates/ - (MISC) https://semiconductor.samsung.com/support/quality-support/product-security-updates/ - Vendor Advisory
CWE CWE-669
First Time Samsung exynos 5123
Samsung exynos 5123 Firmware
Samsung
Samsung exynos 5300 Firmware
Samsung exynos 5300
CPE cpe:2.3:h:samsung:exynos_5123:-:*:*:*:*:*:*:*
cpe:2.3:o:samsung:exynos_5300_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:samsung:exynos_5300:-:*:*:*:*:*:*:*
cpe:2.3:o:samsung:exynos_5123_firmware:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1

07 Jun 2023, 21:36

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-07 21:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-31114

Mitre link : CVE-2023-31114

CVE.ORG link : CVE-2023-31114


JSON object : View

Products Affected

samsung

  • exynos_5300_firmware
  • exynos_5300
  • exynos_5123_firmware
  • exynos_5123
CWE
CWE-669

Incorrect Resource Transfer Between Spheres