Samsung
Samsung Mtower: vulnerabilidades y CVE
Samsung Mtower tiene 16 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses3
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-10420 | Media (5.5) | 0.11% | — | 1 sept 2026 | Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 102d3dc75cf8e58e68e4bea54ae3c803992c91be. |
| CVE-2026-82927 | Media (5.5) | 0.15% | — | 1 sept 2026 | Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 06994e303637512e39062f3e037c222e8448e57e. |
| CVE-2026-82926 | Media (5.5) | 0.15% | — | 1 sept 2026 | NULL pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before afef59aa6f55c5d5ebf9b14bc020bf1c2c37489a. |
| CVE-2022-40762 | Alta (7.5) | 1.0% | — | 16 sept 2022 | A Memory Allocation with Excessive Size Value vulnerablity in the TEE_Realloc function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function… |
| CVE-2022-40761 | Alta (7.5) | 1.7% | — | 16 sept 2022 | The function tee_obj_free in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEE_AllocateOperation with a disturbed heap layout, related to… |
| CVE-2022-40760 | Alta (7.5) | 1.4% | — | 16 sept 2022 | A Buffer Access with Incorrect Length Value vulnerablity in the TEE_MACUpdate function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function… |
| CVE-2022-40759 | Alta (7.5) | 1.0% | — | 16 sept 2022 | A NULL pointer dereference issue in the TEE_MACCompareFinal function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEE_MACCompareFinal with a… |
| CVE-2022-40758 | Alta (7.5) | 1.0% | — | 16 sept 2022 | A Buffer Access with Incorrect Length Value vulnerablity in the TEE_CipherUpdate function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function… |
| CVE-2022-40757 | Alta (7.5) | 1.0% | — | 16 sept 2022 | A Buffer Access with Incorrect Length Value vulnerablity in the TEE_MACComputeFinal function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function… |
| CVE-2022-39830 | Alta (7.5) | 1.3% | — | 5 sept 2022 | sign_pFwInfo in Samsung mTower through 0.3.0 has a missing check on the return value of EC_KEY_set_public_key_affine_coordinates, leading to a denial of service. |
| CVE-2022-39829 | Alta (7.5) | 1.3% | — | 5 sept 2022 | There is a NULL pointer dereference in aes256_encrypt in Samsung mTower through 0.3.0 due to a missing check on the return value of EVP_CIPHER_CTX_new. |
| CVE-2022-39828 | Alta (7.5) | 1.3% | — | 5 sept 2022 | sign_pFwInfo in Samsung mTower through 0.3.0 has a missing check on the return value of EC_KEY_set_private_key, leading to a denial of service. |
| CVE-2022-36622 | Alta (7.5) | 1.4% | — | 1 sept 2022 | Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEE_GetObjectInfo1. |
| CVE-2022-36621 | Alta (7.5) | 1.3% | — | 1 sept 2022 | Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEE_AllocateTransientObject. |
| CVE-2022-38155 | Alta (7.5) | 1.0% | — | 11 ago 2022 | TEE_Malloc in Samsung mTower through 0.3.0 allows a trusted application to achieve Excessive Memory Allocation via a large len value, as demonstrated by a Numaker-PFM-M2351 TEE kernel crash. |
| CVE-2022-35858 | Alta (7.8) | 0.40% | — | 4 ago 2022 | The TEE_PopulateTransientObject and __utee_from_attr functions in Samsung mTower 0.3.0 allow a trusted application to trigger a memory overwrite, denial of service, and information disclosure by invoking the function… |