CVE-2023-37366

LOW CVSS 3.1: 2.8 EPSS 0.09%
Updated Sep 16, 2026
Samsung
Parameter Value
CVSS 2.8 (LOW)
Affected Versions before 2023-04-28
Type CWE-835
Vendor Samsung
Public PoC No

An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos Modem 5123, Exynos Modem 5300, an Exynos Auto T5123. In the Shannon SM Task, improper handling of a loop with an unreachable exit condition cannot guarantee the termination of a required service via a malformed SM message.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
High
Difficult to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
Low
Partial disruption

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Samsung Exynos_850_Firmware
cpe:2.3:a:samsung:exynos_850_firmware:*:*:*:*:*:*:*:*
<= 2023-04-28