← All Advisories

Samsung Exynos USIM improper SIM proactive command handling causes denial of service

Last refreshed2026-09-30

Status: UPDATED  |  Advisory ID: CVE-2025-59440

Key Details

CVECVE-2025-59440
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-06-17
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high.
Affected productssee table below
Classified asCWE-400 (Uncontrolled Resource Consumption)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Samsungexynos_990_firmware
Samsungexynos_980_firmware
Samsungexynos_850_firmware
Samsungexynos_1080_firmware
Samsungexynos_1280_firmware
Samsungexynos_1330_firmware
Samsungexynos_1380_firmware
Samsungexynos_1480_firmware
Samsungexynos_1580_firmware
Samsungexynos_2100_firmware
Samsungexynos_2200_firmware
Samsungexynos_2400_firmware
Samsungexynos_2500_firmware
Samsungexynos_w930_firmware
Samsungexynos_w920_firmware
Samsungexynos_w1000_firmware
Samsungexynos_modem_5400_firmware
Samsungexynos_modem_5300_firmware
Samsungexynos_modem_5123_firmware
Samsungexynos_9110_firmware
SubsystemsGeneral OT
SectorsMultiple

What to Know

An issue was discovered in USIM in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. Improper handling of SIM card proactive commands leads to a Denial of Service. (NVD)

What to Do

Monitor Samsung's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2025-59440
CVEhttps://www.cve.org/CVERecord?id=CVE-2025-59440
Vendor advisoryhttps://semiconductor.samsung.com/support/quality-support/product-security-updates/