SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-10751

A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml payload.

MEDIUM 5.3EPSS 8.64%

Does this matter?

Lower severity and a low EPSS score (8.64%). Track it; it rarely justifies an emergency change on its own.

Description

A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml payload. This is due to an integer overflow in memory allocation for this string. The Samsung ID is SVE-2018-11463.

CVSS 3.0
5.3 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS
8.64% probability · 95th percentile
CISA KEV
Not listed
Weakness
CWE-190
Affected
samsung/samsung mobile
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.