Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-20610


An issue was discovered on Samsung mobile devices with N(7.X) and O(8.X) (Exynos 7570, 7870, 7880, 7885, 8890, 8895, and 9810 chipsets) software. A double-fetch vulnerability in Trustlet allows arbitrary TEE code execution. The Samsung ID is SVE-2019-13910 (April 2019).


Published

2020-03-24T20:15:13.757

Last Modified

2024-11-21T04:38:52.287

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.6

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-367

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System google android 7.0 Yes
Operating System google android 7.1.0 Yes
Operating System google android 7.1.1 Yes
Operating System google android 7.1.2 Yes
Operating System google android 8.0 Yes
Operating System google android 8.1 Yes
Hardware samsung exynos_7570 - No
Hardware samsung exynos_7870 - No
Hardware samsung exynos_7880 - No
Hardware samsung exynos_7885 - No
Hardware samsung exynos_8890 - No
Hardware samsung exynos_8895 - No
Hardware samsung exynos_9810 - No

References