CVE-2021-25371
Samsung Mobile Devices Unspecified Vulnerability
Description
CVE-2021-25371 is a hidden functionality vulnerability in the DSP (Digital Signal Processor) driver of Samsung Android mobile devices, present in firmware prior to the SMR Mar-2021 Release 1. This flaw allows attackers to load arbitrary ELF libraries into the DSP, potentially enabling execution of malicious code within a privileged hardware component. CISA has added CVE-2021-25371 to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild with a remediation deadline of July 20, 2023. The EPSS score of 0.90% places this vulnerability in the 75th percentile for exploitation probability, underscoring the importance of applying Samsung security updates to protect mobile devices against this DSP driver vulnerability.
KEV Information
CVSS Score
CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorCWEs
Affected Products
| Vendor | Product | Version |
|---|---|---|
| samsung | android | 10.0; 11.0 |
Multiple CVSS Assessments
CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
References
- https://security.samsungmobile.com(Vendor Advisory)
- https://security.samsungmobile.com/securityUpdate.smsb(Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-25371(US Government Resource)
Weakness Type
CWE-912: Hidden Functionality
In CVE-2021-25371, the Samsung DSP driver contains hidden functionality that allows loading arbitrary ELF (Executable and Linkable Format) libraries into the DSP processor. This undocumented capability was not intended to be accessible to external parties but can be exploited by an attacker with sufficient privileges and physical access to inject malicious code into the DSP, bypassing normal security controls that govern code execution on the device.
Learn more: CWE-912 — Hidden Functionality
Impact Analysis
CVE-2021-25371 carries a CVSS v3.1 score of 6.1 (Medium severity), reflecting the constrained but impactful nature of this vulnerability. The attack requires physical access (Attack Vector: Physical) to the Samsung device, significantly limiting the pool of potential attackers. Combined with high attack complexity and the need for high privileges, the exploitation prerequisites are substantial. However, no user interaction is required, meaning exploitation can proceed silently once physical access and privileges are obtained. The impact upon successful exploitation is severe across all three dimensions: Confidentiality (High) means sensitive data processed by the DSP, including audio streams and sensor data, could be intercepted. Integrity (High) indicates an attacker can load arbitrary ELF libraries, modifying the behavior of the DSP to execute malicious code. Availability (High) means the DSP subsystem could be disrupted or rendered inoperable. The scope remains unchanged, limiting impact to the DSP component and its directly dependent functionality. The EPSS score of 0.90% (75th percentile) suggests a non-trivial exploitation probability, and CISA's KEV listing confirms this vulnerability has been exploited in real-world targeted attacks.
Exploit Maturity
CISA has confirmed active exploitation of CVE-2021-25371 by including it in the Known Exploited Vulnerabilities catalog, with a remediation deadline of July 20, 2023. No publicly available exploit code or proof-of-concept has been identified in the referenced vendor advisories, suggesting that exploitation has been conducted through private channels, likely by advanced persistent threat actors with physical access capabilities. The EPSS score of 0.90% (75th percentile) indicates a moderate probability of exploitation, higher than many comparable physical-access vulnerabilities. The ransomware association is classified as unknown. This vulnerability is often discussed alongside CVE-2021-25372, which targets the same Samsung DSP driver with an out-of-bounds memory access flaw, suggesting these two vulnerabilities may have been chained together in real-world attacks.
Remediation
- Apply the Samsung SMR Mar-2021 Release 1 update to all affected Samsung Android devices immediately. Per CISA's KEV directive: apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Verify the security patch level on all Samsung devices in your fleet to ensure the March 2021 or later patch is applied. Check under Settings > About phone > Software information > Android security patch level.
- Restrict physical access to Samsung devices in sensitive environments. Implement physical security controls such as device lockdown policies, secure storage, and tamper-evident seals for devices that process classified or sensitive information.
- Monitor for indicators of compromise by reviewing device logs for unusual DSP activity, unexpected library loading events, or anomalous behavior in audio or sensor subsystems. Deploy endpoint detection and response (EDR) solutions capable of monitoring kernel and hardware-level activity on mobile devices.
- Enforce device integrity checks using Samsung Knox attestation features to verify that the DSP driver and associated firmware components have not been tampered with. Configure MDM policies to automatically quarantine devices that fail integrity checks.
Technical Details
CVE-2021-25371 exploits hidden functionality (CWE-912) within Samsung's DSP (Digital Signal Processor) driver, a kernel-level component that manages the device's dedicated signal processing hardware. The DSP driver contains an undocumented capability that permits loading arbitrary ELF (Executable and Linkable Format) libraries into the DSP processor's execution environment. This hidden functionality bypasses the normal code verification and loading controls that govern what software can run on the DSP. The CVSS vector (AV:P/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H) indicates that exploitation requires physical access to the device along with high privileges and high attack complexity, reflecting the specialized nature of DSP exploitation. An attacker who gains physical access and sufficient privileges can leverage this hidden interface to inject arbitrary code into the DSP, which operates with its own dedicated execution environment and memory space separate from the main application processor. The DSP handles sensitive operations including audio processing, sensor data fusion, and communication signal handling, making compromise of this component particularly valuable for surveillance-oriented threat actors.
Frequently Asked Questions
Is CVE-2021-25371 being actively exploited?
Yes, CISA has confirmed active exploitation of CVE-2021-25371 by adding it to the Known Exploited Vulnerabilities catalog. The mandated remediation deadline was July 20, 2023. The exploitation appears to be targeted rather than widespread, consistent with the physical access requirement.
What products are affected by CVE-2021-25371?
CVE-2021-25371 affects Samsung Android mobile devices running firmware prior to the SMR Mar-2021 Release 1. Specifically, devices with the vulnerable DSP driver component are at risk when an attacker has physical access to the device.
How do I fix CVE-2021-25371?
Update all Samsung Android devices to the SMR Mar-2021 Release 1 or later security patch level. Verify the patch by checking the Android security patch level in device settings. Additionally, restrict physical access to devices in sensitive environments and enable Samsung Knox integrity verification features.
How severe is CVE-2021-25371?
CVE-2021-25371 has a CVSS v3.1 score of 6.1, rated as Medium severity. While the physical access requirement limits broad exploitation, successful attacks fully compromise confidentiality, integrity, and availability of the DSP subsystem. The EPSS score of 0.90% (75th percentile) and CISA KEV listing indicate real-world exploitation despite the access constraints.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.