CVE-2025-32100
BaseFortify
Publication date: 2025-09-02
Last updated on: 2025-09-05
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| samsung | exynos_980_firmware | * |
| samsung | exynos_980 | * |
| samsung | exynos_990_firmware | * |
| samsung | exynos_990 | * |
| samsung | exynos_850_firmware | * |
| samsung | exynos_850 | * |
| samsung | exynos_1080_firmware | * |
| samsung | exynos_1080 | * |
| samsung | exynos_2100_firmware | * |
| samsung | exynos_2100 | * |
| samsung | exynos_1280_firmware | * |
| samsung | exynos_1280 | * |
| samsung | exynos_2200_firmware | * |
| samsung | exynos_2200 | * |
| samsung | exynos_1330_firmware | * |
| samsung | exynos_1330 | * |
| samsung | exynos_1380_firmware | * |
| samsung | exynos_1380 | * |
| samsung | exynos_1480_firmware | * |
| samsung | exynos_1480 | * |
| samsung | exynos_2400_firmware | * |
| samsung | exynos_2400 | * |
| samsung | exynos_1580_firmware | * |
| samsung | exynos_1580 | * |
| samsung | exynos_9110_firmware | * |
| samsung | exynos_9110 | * |
| samsung | exynos_w920_firmware | * |
| samsung | exynos_w920 | * |
| samsung | exynos_w930_firmware | * |
| samsung | exynos_w930 | * |
| samsung | exynos_w1000_firmware | * |
| samsung | exynos_w1000 | * |
| samsung | modem_5123_firmware | * |
| samsung | modem_5123 | * |
| samsung | modem_5300_firmware | * |
| samsung | modem_5300 | * |
| samsung | modem_5400_firmware | * |
| samsung | modem_5400 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-125 | The product reads data past the end, or before the beginning, of the intended buffer. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a programming error in Samsung's Exynos processors and modems involving the ROHC (Robust Header Compression) component. Specifically, a buffer copy operation is flawed, leading to out-of-bounds writes when processing malformed ROHC packets. This means the software writes data outside the intended memory area, which can cause memory corruption or other security issues. [1]
How can this vulnerability impact me? :
The vulnerability can lead to memory corruption or other security issues on affected Samsung Exynos processors and modems. This could potentially be exploited to cause device instability, crashes, or unauthorized code execution, impacting device security and reliability. [1]