9.8
CVSSv3

CVE-2020-25279

Published: 11/09/2020 Updated: 21/09/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. The baseband component has a buffer overflow via an abnormal SETUP message, leading to execution of arbitrary code. The Samsung ID is SVE-2020-18098 (September 2020).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google android 8.0

google android 8.1

google android 9.0

google android 10.0

Github Repositories

What is BVFinder? BVFinder is a baseband firmware static vulnerability prototype detection tool developed based on BinAbsInspector It identifies a vulnerability by locating whether a predefined sensitive memory operation is tainted by any attacker-controllable input Specifically, to reach high automation and preciseness, it made two key improvements: a semantic-based taint so