CVE-2023-37366
Summary
| CVE | CVE-2023-37366 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-14 06:16:53 UTC |
| Updated | 2026-09-14 06:16:53 UTC |
| Description | An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos Modem 5123, Exynos Modem 5300, an Exynos Auto T5123. In the Shannon SM Task, improper handling of a loop with an unreachable exit condition cannot guarantee the termination of a required service via a malformed SM message. |
Risk And Classification
Primary CVSS: v3.1 2.8 LOW from [email protected]
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L
EPSS: 0.000910000 probability, percentile 0.005400000 (date 2026-09-14)
Problem Types: CWE-835 | CWE-835 CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 2.8 | LOW | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L |
| 3.1 | CNA | CVSS | 2.8 | LOW | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
HighPrivileges Required
LowUser Interaction
NoneScope
ChangedConfidentiality
NoneIntegrity
NoneAvailability
LowCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Samsung | Exynos 850 Firmware | affected 2023-04-28 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2023-37366 | [email protected] | semiconductor.samsung.com | |
| semiconductor.samsung.com/support/quality-support/product-security-updates | [email protected] | semiconductor.samsung.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.