Technical Severity
MEDIUM
CVSS v3.1 Metrics
6.2
/ 10
Minimal Risk
Critical
Vector Specification
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitation Likelihood
EPSS Prediction
0.16
%
Predictive Probability
Percentile Rank
36.6
th
Documented as more likely to be exploited than 36.6% of known CVEs.
Detection Date
Nov 08, 2022
Remediation Due
Nov 29, 2022
CISA Catalog Active
Threat Analysis
Samsung mobile devices using Mali GPU contains an improper access control vulnerability in sec_log file. Exploitation of the vulnerability exposes sensitive kernel information to the userspace. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25370.
Remediation Directive
Apply updates per vendor instructions.