CVE-2022-28793

Published May 3, 2022

Last updated 3 months ago

Overview

Description
Given the TEE is compromised and controlled by the attacker, improper state maintenance in StrongBox allows attackers to change Android ROT during device boot cycle after compromising TEE. The patch is applied in Galaxy S22 to prevent change of Android ROT after first initialization at boot time.
Source
mobile.security@samsung.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
4.4
Impact score
3.6
Exploitability score
0.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Severity
MEDIUM

CVSS 2.0

Type
Primary
Base score
2.1
Impact score
2.9
Exploitability score
3.9
Vector string
AV:L/AC:L/Au:N/C:N/I:P/A:N

Weaknesses

mobile.security@samsung.com
CWE-754
nvd@nist.gov
CWE-754

Social media

Hype score
Not currently trending

Configurations