PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-37366 Samsung CVE debrief

A low-severity vulnerability was discovered in various Samsung Exynos processors, including Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. The issue involves improper handling of a loop with an unreachable exit condition in the Shannon SM Task, which could potentially lead to a denial of service via a malformed SM message. This vulnerability has a CVSS score of 2.8 and is considered low-severity. Defenders should prioritize verifying the vulnerability status of affected processors, assessing exposure,

Vendor
Samsung
Product
Exynos 850 firmware
CVSS
LOW 2.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-14
Original CVE updated
2026-09-22
Advisory published
2026-09-14
Advisory updated
2026-09-22

Who should care

Defenders responsible for securing systems that utilize affected Exynos processors should assess their exposure and prioritize verification of the vulnerability status. They should also monitor for potential denial-of-service attacks and apply patches or mitigations as available.

Why it matters

A low-severity vulnerability in Samsung Exynos processors could lead to denial of service via a malformed SM message. Defenders should prioritize verifying the vulnerability status of affected processors, assessing exposure, and applying patches or mitigations as available.

  • Denial of service via malformed SM message
  • Potential disruption of services relying on affected Exynos processors
  • Need for verification of vulnerability status and exposure
  • Priority for applying patches or mitigations

Technical summary

The Shannon SM Task vulnerability affects multiple Exynos processors, including Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. The vulnerability involves improper handling of a loop with an unreachable exit condition, which could potentially lead to a denial of service via a malformed SM message.

Defensive priority

Defenders should prioritize verifying the vulnerability status of affected Exynos processors and assessing their exposure. They should also monitor for potential denial-of-service attacks and apply patches or mitigations as available.

Recommended defensive actions

  • Verify the vulnerability status of affected Exynos processors
  • Assess exposure and apply patches or mitigations as available
  • Monitor for potential denial-of-service attacks
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability. The Shannon SM Task vulnerability affects multiple Exynos processors, but specific details about exploitation or impact are not provided.

Sources and references

Verified primary and authoritative sources

  • CVE-2023-37366 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2023-37366

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2023-37366 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2023-37366

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.