Junglewise Threat Intelligence

CVE-2021-25371: Samsung Mobile Devices Unspecified Vulnerability

CVE-2021-25371 · Severity: critical · CVSS 6.7 · Exploited in the wild · Published 2023-06-29

Technologies: Samsung Mobile Devices, Samsung Exynos 980, Samsung Exynos 2100, Google Android. Vendors: Samsung, Google.

Executive brief

Samsung mobile devices contain a vulnerability in the DSP driver that allows an attacker with high privileges to load arbitrary ELF libraries inside the Digital Signal Processor (DSP). This flaw can lead to a complete loss of confidentiality, integrity, and availability within the DSP environment.

Affected products

  • Google Android 10.0, 11.0
  • Samsung Exynos 2100
  • Samsung Exynos 980
  • Samsung Exynos 9830

Timeline

  • 2021-03-26: disclosed
  • 2021-03-26: advisory: NVD Published Date
  • 2021-03-01: patched: SMR Mar-2021 Release 1
  • 2023-06-29: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog

Related threats