Samsung Exynos Processors and Modems Lack Boundary Check in DL NAS Transport Message Decoding Leading to Denial-of-Service

Vulnerability

A denial-of-service vulnerability has been identified in NRMM across various Samsung mobile processors, wearable processors, and modems, including the Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. The issue arises from a lack of boundary checks during the decoding of DL NAS Transport messages, which can be exploited to cause a denial-of-service condition.

Impact

Exploitation of this vulnerability leads to a denial-of-service condition, causing affected devices to become unresponsive or unavailable.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
2.5
exploitability
4.7
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.