CVE-2024-46921
MEDIUMDescription
An issue was discovered in Samsung Mobile Processor and Modem Exynos 9820, 9825, 980, 990, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W1000, Modem 5123, Modem 5300, Modem 5400. UE does not limit the number of attempts for the RRC Setup procedure in the 5G SA, leading to a denial of service (battery-drain attack).
Is your site exposed to CVE-2024-46921?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| samsung | exynos_1080_firmware |
| samsung | exynos_1080 |
| samsung | exynos_1280_firmware |
| samsung | exynos_1280 |
| samsung | exynos_1330_firmware |
| samsung | exynos_1330 |
| samsung | exynos_1380_firmware |
| samsung | exynos_1380 |
| samsung | exynos_1480_firmware |
| samsung | exynos_1480 |
| samsung | exynos_2100_firmware |
| samsung | exynos_2100 |
| samsung | exynos_2200_firmware |
| samsung | exynos_2200 |
| samsung | exynos_2400_firmware |
| samsung | exynos_2400 |
| samsung | exynos_9110_firmware |
| samsung | exynos_9110 |
| samsung | exynos_980_firmware |
| samsung | exynos_980 |
| samsung | exynos_9820_firmware |
| samsung | exynos_9820 |
| samsung | exynos_9825_firmware |
| samsung | exynos_9825 |
| samsung | exynos_990_firmware |
| samsung | exynos_990 |
| samsung | exynos_modem_5123_firmware |
| samsung | exynos_modem_5123 |
| samsung | exynos_modem_5300_firmware |
| samsung | exynos_modem_5300 |
| samsung | exynos_modem_5400_firmware |
| samsung | exynos_modem_5400 |
| samsung | exynos_w1000_firmware |
| samsung | exynos_w1000 |
References
Frequently Asked Questions
What is CVE-2024-46921? +
How severe is CVE-2024-46921? +
What products are affected by CVE-2024-46921? +
How do I check if I'm vulnerable to CVE-2024-46921? +
Related Vulnerabilities
mcp-framework is a framework for building Model Context Protocol (MCP) servers. In versions 0.2.21 and below, the readRequestBody() function in …
spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser …
Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion. …
Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion …
Allocation of Resources Without Limits or Throttling vulnerability in elixir-plug plug_cowboy allows unauthenticated remote denial of service via atom table …
A denial-of-service security issue exists in 1734 POINT I/O™ module. The security issue stems from improper handling of crafted CIP …