CVE-2025-47202
BaseFortify
Publication date: 2025-07-07
Last updated on: 2025-10-27
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| samsung | exynos_1080_firmware | * |
| samsung | exynos_980_firmware | * |
| samsung | exynos_980 | * |
| samsung | exynos_990_firmware | * |
| samsung | exynos_990 | * |
| samsung | exynos_850_firmware | * |
| samsung | exynos_850 | * |
| samsung | exynos_2100_firmware | * |
| samsung | exynos_2100 | * |
| samsung | exynos_2200_firmware | * |
| samsung | exynos_2200 | * |
| samsung | exynos_2400_firmware | * |
| samsung | exynos_2400 | * |
| samsung | exynos_1580_firmware | * |
| samsung | exynos_1580 | * |
| samsung | exynos_1080 | * |
| samsung | exynos_1280_firmware | * |
| samsung | exynos_1280 | * |
| samsung | exynos_1330_firmware | * |
| samsung | exynos_1330 | * |
| samsung | exynos_1380_firmware | * |
| samsung | exynos_1380 | * |
| samsung | exynos_1480_firmware | * |
| samsung | exynos_1480 | * |
| samsung | exynos_9110_firmware | * |
| samsung | exynos_9110 | * |
| samsung | exynos_w1000_firmware | * |
| samsung | exynos_w1000 | * |
| samsung | exynos_w920_firmware | * |
| samsung | exynos_w920 | * |
| samsung | exynos_w930_firmware | * |
| samsung | exynos_w930 | * |
| samsung | modem_5123_firmware | * |
| samsung | modem_5123 | * |
| samsung | modem_5300_firmware | * |
| samsung | modem_5300 | * |
| samsung | modem_5400_firmware | * |
| samsung | modem_5400 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-787 | The product writes data past the end, or before the beginning, of the intended buffer. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
CVE-2025-47202 is a high-severity vulnerability in multiple Samsung Exynos processors and modem chips. It is caused by a lack of proper length checking in the Radio Resource Control (RRC) component, which leads to out-of-bounds write operations. This means that the system may write data outside the intended memory boundaries, potentially causing memory corruption or other security issues. [1]
How can this vulnerability impact me? :
This vulnerability can lead to memory corruption or other security issues on affected Samsung Semiconductor products. Such memory corruption could be exploited to cause system instability, crashes, or potentially allow attackers to execute arbitrary code or escalate privileges, impacting the security and reliability of devices using the affected processors or modems. [1]