{"api_version":"1","generated_at":"2026-07-24T17:17:09+00:00","cve":"CVE-2022-36622","urls":{"html":"https://cve.report/CVE-2022-36622","api":"https://cve.report/api/cve/CVE-2022-36622.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-36622","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-36622"},"summary":{"title":"CVE-2022-36622","description":"Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEE_GetObjectInfo1.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2022-09-01 21:15:00","updated_at":"2022-09-07 13:58:00"},"problem_types":["CWE-476"],"metrics":[],"references":[{"url":"https://github.com/Samsung/mTower/blob/18f4b592a8a973ce5972f4e2658ea0f6e3686284/tee/lib/libutee/tee_api_objects.c#L84","name":"https://github.com/Samsung/mTower/blob/18f4b592a8a973ce5972f4e2658ea0f6e3686284/tee/lib/libutee/tee_api_objects.c#L84","refsource":"MISC","tags":[],"title":"mTower/tee_api_objects.c at 18f4b592a8a973ce5972f4e2658ea0f6e3686284 · Samsung/mTower · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/Samsung/mTower/blob/18f4b592a8a973ce5972f4e2658ea0f6e3686284/tee/tee/tee_svc.c#L965","name":"https://github.com/Samsung/mTower/blob/18f4b592a8a973ce5972f4e2658ea0f6e3686284/tee/tee/tee_svc.c#L965","refsource":"MISC","tags":[],"title":"mTower/tee_svc.c at 18f4b592a8a973ce5972f4e2658ea0f6e3686284 · Samsung/mTower · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://security.samsungmobile.com/securityUpdate.smsb","name":"https://security.samsungmobile.com/securityUpdate.smsb","refsource":"MISC","tags":[],"title":"Samsung Mobile Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/Samsung/mTower","name":"https://github.com/Samsung/mTower","refsource":"MISC","tags":[],"title":"GitHub - Samsung/mTower: mTower is Trusted Execution Environment specially designed to be used on MicroController Units (MCUs) supporting ARM TrustZone technology (e.g., Cortex-M23/33/35p). mTower operates well under restrictions typical for such environment – small RAM and ROM sizes, relatively low performance, absence of rich OSes providing variety of services available on PCs or in enterprise environments. mTower is intended for usage in IoT, embedded devices, Smart Home applications, distributed heterog","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-36622","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-36622","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2022","cve_id":"36622","vulnerable":"1","versionEndIncluding":"0.3.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"samsung","cpe5":"mtower","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2022-36622","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEE_GetObjectInfo1."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://security.samsungmobile.com/securityUpdate.smsb","refsource":"MISC","name":"https://security.samsungmobile.com/securityUpdate.smsb"},{"url":"https://github.com/Samsung/mTower","refsource":"MISC","name":"https://github.com/Samsung/mTower"},{"url":"https://github.com/Samsung/mTower/blob/18f4b592a8a973ce5972f4e2658ea0f6e3686284/tee/lib/libutee/tee_api_objects.c#L84","refsource":"MISC","name":"https://github.com/Samsung/mTower/blob/18f4b592a8a973ce5972f4e2658ea0f6e3686284/tee/lib/libutee/tee_api_objects.c#L84"},{"url":"https://github.com/Samsung/mTower/blob/18f4b592a8a973ce5972f4e2658ea0f6e3686284/tee/tee/tee_svc.c#L965","refsource":"MISC","name":"https://github.com/Samsung/mTower/blob/18f4b592a8a973ce5972f4e2658ea0f6e3686284/tee/tee/tee_svc.c#L965"}]}},"nvd":{"publishedDate":"2022-09-01 21:15:00","lastModifiedDate":"2022-09-07 13:58:00","problem_types":["CWE-476"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:samsung:mtower:*:*:*:*:*:*:*:*","versionEndIncluding":"0.3.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}