VDB

CVE-2020-8860

CVE-2020-8860 PUBLISHED CVSS 7.099999904632568 HIGH

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung Galaxy S10 Firmware G973FXXS3ASJA, O(8.x), P(9.0), Q(10.0) devices with Exynos chipsets. User interaction is required to exploit this vulnerability in that the target must answer a phone call. The specific flaw exists within the Call Control Setup messages. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length, stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the baseband processor. Was ZDI-CAN-9658.

EPSS 0.71% · 52.2th percentile

Risk Scores

CVSS 3.0
7.099999904632568
CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
0.71%
52.2th percentile

Affected Products

VendorProductVersions
SamsungGalaxy S10Firmware G973FXXS3ASJA, O(8.x), P(9.0), Q(10.0) devices with Exynos chipsets
googleandroid8.1, 9.0, 10.0

Timeline

  • Feb 20, 2020 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 25, 2021 EPSS Score
  • Dec 29, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 2, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 4, 2022 EPSS Score
  • Sep 8, 2022 EPSS Score
  • Nov 10, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›