Skip to main content

Vendor/product archive

samsung / mtower CVEs

Beta · best-effort

13 CVEs tagged to samsung / mtower0 Critical, 13 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2022-40762

Published Sep 16, 2022

A Memory Allocation with Excessive Size Value vulnerablity in the TEE_Realloc function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-40761

Published Sep 16, 2022

The function tee_obj_free in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEE_AllocateOperation with a d…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-40760

Published Sep 16, 2022

A Buffer Access with Incorrect Length Value vulnerablity in the TEE_MACUpdate function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-40759

Published Sep 16, 2022

A NULL pointer dereference issue in the TEE_MACCompareFinal function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-40758

Published Sep 16, 2022

A Buffer Access with Incorrect Length Value vulnerablity in the TEE_CipherUpdate function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Servi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-40757

Published Sep 16, 2022

A Buffer Access with Incorrect Length Value vulnerablity in the TEE_MACComputeFinal function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Se…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-39830

Published Sep 5, 2022

sign_pFwInfo in Samsung mTower through 0.3.0 has a missing check on the return value of EC_KEY_set_public_key_affine_coordinates, leading to a denial of service.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-39829

Published Sep 5, 2022

There is a NULL pointer dereference in aes256_encrypt in Samsung mTower through 0.3.0 due to a missing check on the return value of EVP_CIPHER_CTX_new.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-39828

Published Sep 5, 2022

sign_pFwInfo in Samsung mTower through 0.3.0 has a missing check on the return value of EC_KEY_set_private_key, leading to a denial of service.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36622

Published Sep 1, 2022

Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEE_GetObjectInfo1.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36621

Published Sep 1, 2022

Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEE_AllocateTransientObject.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-38155

Published Aug 11, 2022

TEE_Malloc in Samsung mTower through 0.3.0 allows a trusted application to achieve Excessive Memory Allocation via a large len value, as demonstrated by a Numaker-PFM-M2351 TEE ke…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-35858

Published Aug 4, 2022

The TEE_PopulateTransientObject and __utee_from_attr functions in Samsung mTower 0.3.0 allow a trusted application to trigger a memory overwrite, denial of service, and informatio…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1