Vulnerabilities > CVE-2022-39829 - NULL Pointer Dereference vulnerability in Samsung Mtower 0.1.0/0.2.0/0.3.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
samsung
CWE-476

Summary

There is a NULL pointer dereference in aes256_encrypt in Samsung mTower through 0.3.0 due to a missing check on the return value of EVP_CIPHER_CTX_new.

Vulnerable Configurations

Part Description Count
Application
Samsung
3

Common Weakness Enumeration (CWE)