vendor:
S7 Edge
by:
Anonymous
7.5
CVSS
HIGH
Integer Overflow
190
CWE
Product Name: S7 Edge
Affected Version From: NRD90M.G93FXXU1DQJ8
Affected Version To: NRD90M.G93FXXU1DQJ8
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Android
2020
OMACP WAP Push Message Memory Corruption
A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml payload. This is due to an integer overflow in memory allocation for this string. While OMACP WAP pushes require authentication, the entire WbXml payload of a push is parsed to extract the credentials, so this bug occurs pre-authentication.
Mitigation:
Ensure that all OMACP WAP push messages are properly validated and authenticated before processing.