Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-19273


On Samsung mobile devices with O(8.0) and P(9.0) software and an Exynos 8895 chipset, RKP (aka the Samsung Hypervisor EL2 implementation) allows arbitrary memory write operations. The Samsung ID is SVE-2019-16265.


Published

2020-02-04T16:15:12.830

Last Modified

2024-11-21T04:34:28.390

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System google android 8.0 Yes
Operating System google android 9.0 Yes
Hardware samsung galaxy_note8 - No
Hardware samsung galaxy_s8 - No
Hardware samsung galaxy_s8_plus - No
Hardware samsung exynos_8895 - Yes

References