CVE-2024-25074

An issue was discovered in Samsung Semiconductor Mobile Processor and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos W930, Exynos Modem 5123, Exynos Modem 5300. The baseband software does not properly check a pointer specified by the SM (Session Management module), which can lead to Denial of Service (Untrusted Pointer Dereference).

Published: 2024-09-10 Last update: 2025-07-01 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2024-25074 is rated Moderate Risk (49.4/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.77%). Mandatory action: Review affected assets and schedule remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2024-25074

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-11-21 0.42% 0.77% +0.36%
2 2025-11-18 0.77% 0.42% -0.36%
3 2025-11-01 0.77%

Full EPSS history (10 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2024-25074

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
5.9 3.1 MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:H)
Even with access, the exploit needs extra luck, timing, or a fussy environment to actually work.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:N)
Doesn’t really leak secrets in a meaningful way.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
2.2 3.6 [email protected]

Weakness enumeration for CVE-2024-25074

Affected software / configurations for CVE-2024-25074

Vendor Product Version Raw CPE
samsung exynos_9820_firmware cpe:2.3:o:samsung:exynos_9820_firmware:-:*:*:*:*:*:*:*
samsung exynos_9825_firmware cpe:2.3:o:samsung:exynos_9825_firmware:-:*:*:*:*:*:*:*
samsung exynos_980_firmware cpe:2.3:o:samsung:exynos_980_firmware:-:*:*:*:*:*:*:*
samsung exynos_990_firmware cpe:2.3:o:samsung:exynos_990_firmware:-:*:*:*:*:*:*:*
samsung exynos_850_firmware cpe:2.3:o:samsung:exynos_850_firmware:-:*:*:*:*:*:*:*
samsung exynos_1080_firmware cpe:2.3:o:samsung:exynos_1080_firmware:-:*:*:*:*:*:*:*
samsung exynos_2100_firmware cpe:2.3:o:samsung:exynos_2100_firmware:-:*:*:*:*:*:*:*
samsung exynos_2200_firmware cpe:2.3:o:samsung:exynos_2200_firmware:-:*:*:*:*:*:*:*
samsung exynos_1280_firmware cpe:2.3:o:samsung:exynos_1280_firmware:-:*:*:*:*:*:*:*
samsung exynos_1380_firmware cpe:2.3:o:samsung:exynos_1380_firmware:-:*:*:*:*:*:*:*
samsung exynos_1330_firmware cpe:2.3:o:samsung:exynos_1330_firmware:-:*:*:*:*:*:*:*
samsung exynos_9110_firmware cpe:2.3:o:samsung:exynos_9110_firmware:-:*:*:*:*:*:*:*
samsung exynos_w920_firmware cpe:2.3:o:samsung:exynos_w920_firmware:-:*:*:*:*:*:*:*
samsung exynos_w930_firmware cpe:2.3:o:samsung:exynos_w930_firmware:-:*:*:*:*:*:*:*
samsung exynos_modem_5123_firmware cpe:2.3:o:samsung:exynos_modem_5123_firmware:-:*:*:*:*:*:*:*
samsung exynos_modem_5300_firmware cpe:2.3:o:samsung:exynos_modem_5300_firmware:-:*:*:*:*:*:*:*

References for CVE-2024-25074

cvelogic Threat Intelligence