Vulnerabilities > CVE-2023-21500 - Double Free vulnerability in Samsung Android 13.0

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
local
low complexity
samsung
CWE-415

Summary

Double free validation vulnerability in setPinPadImages in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to access the trustlet memory.

Vulnerable Configurations

Part Description Count
OS
Samsung
8

Common Weakness Enumeration (CWE)