CVE-2022-39901 — Improper Authentication in Mobile Devices
Severity
6.5MEDIUMNVD
EPSS
0.2%
top 56.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 8
Latest updateJun 1
Description
Improper authentication in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to disable the network traffic encryption between UE and gNodeB.
CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6
Affected Packages1 packages
🔴Vulnerability Details
3OSV▶
CVE-2022-39901: In TBD of TBD, there is a possible downgrade attack against cryptography in a 5G NSA network due to a logic error in the code↗2023-06-01
GHSA▶
GHSA-cgvm-v5x3-2hm9: Improper authentication in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to disable the network traffic encryption between UE↗2022-12-08
CVEList▶
CVE-2022-39901: Improper authentication in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to disable the network traffic encryption between UE↗2022-12-08