CVE-2021-25444Improper Input Validation in Mobile Devices

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 92.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 5
Latest updateMay 24

Description

An IV reuse vulnerability in keymaster prior to SMR AUG-2021 Release 1 allows decryption of custom keyblob with privileged process.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5samsung_mobile/samsung_mobile_devicesO(8.1), P(9.0), Q(10.0)SMR AUG-2021 Release 1
NVDgoogle/android10.0, 8.1, 9.0+2

🔴Vulnerability Details

2
GHSA
GHSA-p3rp-7c36-7fjf: An IV reuse vulnerability in keymaster prior to SMR AUG-2021 Release 1 allows decryption of custom keyblob with privileged process2022-05-24
CVEList
CVE-2021-25444: An IV reuse vulnerability in keymaster prior to SMR AUG-2021 Release 1 allows decryption of custom keyblob with privileged process2021-08-05

🕵️Threat Intelligence

2
Trailofbits
Themes from Real World Crypto 20222022-05-03
Trailofbits
Themes from Real World Crypto 20222022-05-03
CVE-2021-25444 — Improper Input Validation | cvebase