Vulnerability Details CVE-2023-21422
Improper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attackers to set custom DNS server without permission via binding WifiService.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 13.5%
CVSS Severity
CVSS v3 Score 5.7
Products affected by CVE-2023-21422
-
cpe:2.3:o:samsung:android:11.0
-
cpe:2.3:o:samsung:android:12.0