← לוח פגיעויות

CVE-2023-21492

בינונית 4.4 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Samsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.

מדדים

CVSS 3.1
4.4 (MEDIUM) מקור הציון: NVD CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
EPSS — סבירות ניצול
3% (אחוזון 100) נכון ל-25/7/2026
CWE
CWE-532

מוצרים מושפעים

samsung: android

קישורים