Technical Severity
MEDIUMCVSS v3.1 Metrics
6.2
/ 10
Minimal Risk
Critical
Vector Specification
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitation Likelihood
EPSS Prediction
0.21
%
Predictive Probability
Percentile Rank
43.5
th
Documented as more likely to be exploited than 43.5% of known CVEs.
Detection Date
Nov 08, 2022
Remediation Due
Nov 29, 2022
CISA Catalog Active
Threat Analysis
Samsung mobile devices using Mali GPU contains an improper access control vulnerability in sec_log file. Exploitation of the vulnerability exposes sensitive kernel information to the userspace. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25370.
Remediation Directive
Apply updates per vendor instructions.