TROYANOSYVIRUS
Retour aux CVEs

CVE-2022-28793

MEDIUM
4.4

Description

Given the TEE is compromised and controlled by the attacker, improper state maintenance in StrongBox allows attackers to change Android ROT during device boot cycle after compromising TEE. The patch is applied in Galaxy S22 to prevent change of Android ROT after first initialization at boot time.

Details CVE

Score CVSS v3.14.4
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Vecteur d'attaqueLOCAL
ComplexiteLOW
Privileges requisHIGH
Interaction utilisateurNONE
Publie5/3/2022
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0

Produits affectes

samsung:galaxy_s22samsung:galaxy_s22_firmware

Faiblesses (CWE)

CWE-754CWE-754

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.