CVE-2026-33970
Received Received - Intake

NULL Pointer Dereference in Samsung Exynos Modem and Mobile Processors

Vulnerability report for CVE-2026-33970, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: MITRE

Description

An issue was discovered in NR RRC and L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 1680, W920, W930, W1000, and Modem 5410. In the 5G baseband, a NULL Pointer Dereference occurs when processing a malformed RRC Reconfiguration message.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 16 associated CPEs
Vendor Product Version / Range
samsung exynos_850 *
samsung exynos_1080 *
samsung exynos_2100 *
samsung exynos_1280 *
samsung exynos_2200 *
samsung exynos_1330 *
samsung exynos_1380 *
samsung exynos_1480 *
samsung exynos_2400 *
samsung exynos_1580 *
samsung exynos_2500 *
samsung exynos_1680 *
samsung w920 *
samsung w930 *
samsung w1000 *
samsung modem_5410 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a NULL Pointer Dereference vulnerability in Samsung's 5G baseband processors. It occurs when the system tries to process a malformed Radio Resource Control (RRC) Reconfiguration message. This flaw affects multiple Exynos chipsets and modem models used in mobile and wearable devices.

Detection Guidance

Detection requires monitoring for malformed RRC Reconfiguration messages in 5G baseband traffic. Use network analyzers like Wireshark to inspect 5G control plane traffic for malformed RRC messages targeting Samsung Exynos chipsets. Check logs for NULL pointer dereference errors in NR RRC or L2 layers on affected devices.

Impact Analysis

The vulnerability could cause a denial of service (DoS) condition in affected devices. This means your device might crash or become unresponsive when processing a specific malformed network message. It does not directly expose data but may disrupt normal device functionality.

Mitigation Strategies

Apply security updates from Samsung if available. Isolate affected devices from critical network segments. Monitor for suspicious RRC message patterns. Contact Samsung support for patch availability as no fixes are mentioned in the provided text.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-33970. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart