CVE-2022-39901Improper Authentication in Mobile Devices

Severity
6.5MEDIUMNVD
EPSS
0.2%
top 56.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 8
Latest updateJun 1

Description

Improper authentication in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to disable the network traffic encryption between UE and gNodeB.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages1 packages

CVEListV5samsung_mobile/samsung_mobile_devicesExynos baseband SMR Dec-2022 Release 1

🔴Vulnerability Details

3
OSV
CVE-2022-39901: In TBD of TBD, there is a possible downgrade attack against cryptography in a 5G NSA network due to a logic error in the code2023-06-01
GHSA
GHSA-cgvm-v5x3-2hm9: Improper authentication in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to disable the network traffic encryption between UE2022-12-08
CVEList
CVE-2022-39901: Improper authentication in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to disable the network traffic encryption between UE2022-12-08
CVE-2022-39901 — Improper Authentication | cvebase