PT-2024-18728 · Samsung · Samsung Mobile Devices

CVE-2024-20821

·

Published

2024-05-06

·

Updated

2024-05-07

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Samsung Mobile Devices (affected versions not specified)
Description A vulnerability allows local attackers to reconfigure OTP, enabling them to transit into RMA mode, which disables security features. This attack requires additional privilege to control the Trusted Execution Environment (TEE). The issue is related to a lack of immutable root of trust in OTP hardware.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2024-20821

Affected Products

Samsung Mobile Devices