TROYANOSYVIRUS
Back to CVEs

CVE-2021-25487

HIGHCISA KEV
7.3

Description

Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dereference of invalid function pointer.

CVE Details

CVSS v3.1 Score7.3
SeverityHIGH
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Attack VectorLOCAL
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published10/6/2021
Last Modified10/30/2025
Sourcekev
Honeypot Sightings0

CISA KEV

VendorSamsung
ProductMobile Devices
Vulnerability NameSamsung Mobile Devices Out-of-Bounds Read Vulnerability
KEV Date Added2023-06-29
Remediation Due Date2023-07-20
Ransomware UseUnknown

Affected Products

samsung:android

Weaknesses (CWE)

CWE-125CWE-125

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.