CVE-2026-33970

low

Description

An issue was discovered in NR RRC and L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 1680, W920, W930, W1000, and Modem 5410. In the 5G baseband, a NULL Pointer Dereference occurs when processing a malformed RRC Reconfiguration message.

References

https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2026-33970/

https://semiconductor.samsung.com/support/quality-support/product-security-updates/

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-77174

Details

Source: Mitre, NVD

Published: 2026-09-14

Updated: 2026-09-22

Risk Information

CVSS v2

Base Score: 2.1

Vector: CVSS2#AV:N/AC:H/Au:S/C:N/I:N/A:P

Severity: Low

CVSS v3

Base Score: 3.5

Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L

Severity: Low

EPSS

EPSS: 0.00198