CVE-2021-25415 — Code Injection in Mobile Devices
Severity
5.5MEDIUMNVD
EPSS
0.0%
top 86.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 11
Latest updateMay 24
Description
Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to remap EL2 memory as writable.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 1.8 | Impact: 3.6
Affected Packages2 packages
▶CVEListV5samsung_mobile/samsung_mobile_devicesQ(10.0), R(11.0) devices with Exynos9610, 9810, 9820, 9830 — SMA JUN-2021 Release 1
🔴Vulnerability Details
2GHSA▶
GHSA-jpc8-v624-5p2h: Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to remap EL2 memory as writa↗2022-05-24
CVEList▶
CVE-2021-25415: Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to remap EL2 memory as writa↗2021-06-11