CISA Known Exploited Vulnerability

CVE-2021-25489

Samsung · Mobile Devices

Samsung Mobile Devices Improper Input Validation Vulnerability

Date added
BOD 22-01 due date
CWE CWE-20
Ransomware Unknown

CISA description

Samsung mobile devices contain an improper input validation vulnerability within the modem interface driver that results in a format string bug leading to kernel panic.

Required action

Apply updates per vendor instructions or discontinue use of the product if updates are unavailable