CVE-2025-54329
BaseFortify
Publication date: 2025-11-04
Last updated on: 2025-11-07
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| samsung | exynos_1280_firmware | * |
| samsung | exynos_1280 | * |
| samsung | exynos_1330_firmware | * |
| samsung | exynos_1330 | * |
| samsung | exynos_1380_firmware | * |
| samsung | exynos_1380 | * |
| samsung | exynos_1480_firmware | * |
| samsung | exynos_1480 | * |
| samsung | exynos_1580_firmware | * |
| samsung | exynos_1580 | * |
| samsung | exynos_2100_firmware | * |
| samsung | exynos_2100 | * |
| samsung | exynos_2200_firmware | * |
| samsung | exynos_2200 | * |
| samsung | exynos_2400_firmware | * |
| samsung | exynos_2400 | * |
| samsung | exynos_2500_firmware | * |
| samsung | exynos_2500 | * |
| samsung | exynos_850_firmware | * |
| samsung | exynos_850 | * |
| samsung | exynos_980_firmware | * |
| samsung | exynos_980 | * |
| samsung | exynos_990_firmware | * |
| samsung | exynos_990 | * |
| samsung | exynos_w930_firmware | * |
| samsung | exynos_w930 | * |
| samsung | exynos_w920_firmware | * |
| samsung | exynos_w920 | * |
| samsung | exynos_w1000_firmware | * |
| samsung | exynos_w1000 | * |
| samsung | modem_5123_firmware | * |
| samsung | modem_5123 | * |
| samsung | modem_5300_firmware | * |
| samsung | modem_5300 | * |
| samsung | modem_5400_firmware | * |
| samsung | modem_5400 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-122 | A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc(). |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the NAS component of various Samsung Mobile and Wearable Processors and Modems. It occurs because the function responsible for sending multiple-payload messages, including SMS messages, does not perform proper bounds checking. This flaw can lead to a heap overflow, which is a type of memory corruption.
How can this vulnerability impact me? :
The vulnerability can cause a heap overflow, which may lead to denial of service or potentially allow an attacker to execute arbitrary code or crash the system. According to the CVSS score, it has a high impact on availability but does not affect confidentiality or integrity.