US CISA warns of a Samsung vulnerability under active exploitation
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2004-1464 | Remote DoS in Cisco IOS blocks telnet, SSH, and HTTP management access CVE-2004-1464 is a denial-of-service vulnerability in Cisco IOS that allows a remote attacker to make a device stop accepting new management connections. Once triggered, the device blocks further telnet, reverse telnet, Remote Shell (RSH), and SSH sessions, and in some cases HTTP access, leaving administrators unable to manage the device remotely until the condition is cleared. The CISA data does not specify the exact trigger conditions or the affected IOS version trains, but the flaw is remotely exploitable against devices that expose these management services, and it does not appear to grant code execution or data theft. Organizations running Cisco IOS routers and switches, particularly older or internet-facing devices, are affected. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on 2023-05-19, indicating known exploitation in the wild; no public proof-of-concept is known, and EPSS estimates a 4.7% probability of exploitation in the next 30 days (91st percentile). Do: Apply IOS software updates per Cisco's instructions, as required by CISA's KEV listing (required action: apply updates per vendor instructions); consult Cisco's advisory to identify affected and fixed IOS releases for your device models. As interim mitigation, restrict telnet, reverse telnet, RSH, SSH, and HTTP management access to trusted management networks using ACLs and management-plane protection. Inventory all IOS devices, prioritize internet-facing and older-generation hardware, and monitor for symptoms such as devices refusing new management sessions. | — | 5% | KEV |
| mass≈ hundreds of thousands of internet-exposed IOS devices, out of millions of IOS deployments overall | |
| CVE-2016-6415 | IKEv1 Memory Disclosure (BENIGNCERTAIN) in Cisco IOS, IOS XE, and IOS XR CVE-2016-6415, nicknamed BENIGNCERTAIN, is an information disclosure flaw (CWE-200) in the server-side IKEv1 implementation of Cisco IOS, IOS XE, IOS XR, and Cisco PIX firewalls (Bug IDs CSCvb29204 and CSCvb36055). An unauthenticated remote attacker can trigger it by sending a crafted Security Association (SA) negotiation request to a device's IKEv1 listener, causing the device to leak sensitive information from its memory. The attacker gains access to those leaked memory contents, which may include sensitive secrets such as keys or credentials used by the device. Organizations running affected Cisco IOS 12.2 through 12.4 or 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x or 5.0.x through 5.2.x, or PIX before 7.0 with IKEv1 enabled are affected. The flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2023-05-19, confirming in-the-wild exploitation, and EPSS assigns it an 87.3% probability of exploitation within 30 days (100th percentile). Do: Upgrade affected IOS, IOS XE, and IOS XR devices to fixed releases per Cisco's advisory for CVE-2016-6415, as required by the CISA KEV listing; as an interim mitigation, disable IKEv1 where unused or restrict ISAKMP (UDP 500) access to trusted peers. Inventory internet-facing Cisco routers, switches, and firewalls for IKEv1-enabled configurations, since only devices with IKEv1 enabled are exploitable. | 7.5 | 87% | KEV |
| massroughly 840,000+ exposed Cisco systems (2016 internet-wide scan estimates) | |
| CVE-2023-21492 | Kernel Pointer Leak in Logs Enables ASLR Bypass on Samsung Mobile Devices CVE-2023-21492 is an information disclosure flaw in Samsung mobile devices in which kernel pointers are written to the device log file, a classic CWE-532 'sensitive data in logs' issue. Triggering requires local access with high (privileged) privileges; an attacker or app with such access can read the leaked pointers from the log. The disclosed addresses let the attacker defeat ASLR (address space layout randomization), which is typically used as a stepping stone in a local privilege-escalation or kernel-exploitation chain rather than as a standalone compromise. Affected devices are Samsung mobile devices running Android whose security patch level predates the SMR May-2023 Release 1. Exploitation is confirmed in the wild: CISA added the issue to the Known Exploited Vulnerabilities catalog on 2023-05-19, though no public proof-of-concept is known and any ransomware connection is unknown. Do: Apply Samsung's SMR May-2023 Release 1 security update or later (check Settings > Software update) and confirm the installed security patch level on managed devices. CISA's KEV entry requires applying vendor updates, so prioritize fleet devices used by high-risk or high-value users. Because exploitation requires local privileged access, there is limited remote exposure, but active in-the-wild exploitation makes prompt patching important. | 4.4 | 3% | KEV |
| masson the order of tens of millions of unpatched devices out of hundreds of millions of Samsung Android devices in use (devices not yet updated to SMR May-2023… |
Full article432 words · extracted from securityaffairs.com · click to collapse

US CISA added the vulnerability CVE-2023-21492 flaw affecting Samsung devices to its Known Exploited Vulnerabilities Catalog.
US CISA added the vulnerability CVE-2023-21492 vulnerability (CVSS score: 4.4) affecting Samsung devices to its Known Exploited Vulnerabilities Catalog.
The issue affects Samsung mobile devices running Android 11, 12, and 13, it is described as an insertion of sensitive information into log file vulnerability that allows a privileged, local attacker to conduct an address space layout randomization (ASLR) bypass.
The issue was reported on January 17, 2023, the company addressed the issue by removing kernel pointers in log file.
“Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.” reads the advisory published by Samsung. “Samsung was notified that an exploit for this issue had existed in the wild”
The company did not provide details about the attacks exploiting the flaw, but likely the issue was chained with other vulnerabilities to compromise vulnerable Samsung devices.
CISA also addressed the following issue in the latest turn:
- CVE-2004-1464 – Cisco IOS Denial-of-Service Vulnerability. Cisco IOS contains an unspecified vulnerability that may block further telnet, reverse telnet, Remote Shell (RSH), Secure Shell (SSH), and in some cases, Hypertext Transport Protocol (HTTP) access to the Cisco device.
- CVE-2016-6415 – Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability. Cisco IOS, IOS XR, and IOS XE contain insufficient condition checks in the part of the code that handles Internet Key Exchange version 1 (IKEv1) security negotiation requests. contains an information disclosure vulnerability in the Internet Key Exchange version 1 (IKEv1) that could allow an attacker to retrieve memory contents. Successful exploitation could allow the attacker to retrieve memory contents, which can lead to information disclosure.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix this flaw by June 9, 2023.
We are in the final!
Please vote for Security Affairs (https://securityaffairs.com/) as the best European Cybersecurity Blogger Awards 2022 – VOTE FOR YOUR WINNERS
Vote for me in the sections where is reported Securityaffairs or my name Pierluigi Paganini
Please nominate Security Affairs as your favorite blog.
Nominate Pierluigi Paganini and Security Affairs here here: https://docs.google.com/forms/d/e/1FAIpQLSepvnj8b7QzMdLh7vWEDQDqohjBUsHyn3x3xRdYGCetwVy2DA/viewform
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/146457/security/cisa-warns-samsung-flaw.html