HIGH · 9.3

CVE-2012-6422

The kernel in Samsung Galaxy S2, Galaxy Note 2, MEIZU MX, and possibly other Android devices, when running an Exynos 4210 or 4412 processor, uses weak permissions (0666) for /dev/exynos-mem, which all...

Vulnerability Description

The kernel in Samsung Galaxy S2, Galaxy Note 2, MEIZU MX, and possibly other Android devices, when running an Exynos 4210 or 4412 processor, uses weak permissions (0666) for /dev/exynos-mem, which allows attackers to read or write arbitrary physical memory and gain privileges via a crafted application, as demonstrated by ExynosAbuse.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
MeizuMx-
SamsungGalaxy Note 2-
SamsungGalaxy S2-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-6422?

CVE-2012-6422 is a vulnerability with a CVSS score of 9.3 (HIGH). The kernel in Samsung Galaxy S2, Galaxy Note 2, MEIZU MX, and possibly other Android devices, when running an Exynos 4210 or 4412 processor, uses weak permissions (0666) for /dev/exynos-mem, which all...

How severe is CVE-2012-6422?

CVE-2012-6422 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-6422?

Check the references section above for vendor advisories and patch information. Affected products include: Meizu Mx, Samsung Galaxy Note 2, Samsung Galaxy S2.