Vulnerabilities
Vulnerable Software
Samsung:  Security Vulnerabilities
Improper access control vulnerability in My Files prior to version 13.1.00.193 allows attackers to access arbitrary private files in My Files application.
CVSS Score
5.1
EPSS Score
0.001
Published
2022-06-07
Exposure of Sensitive Information vulnerability in Samsung Account prior to version 13.2.00.6 allows attacker to access sensitive information via onActivityResult.
CVSS Score
5.5
EPSS Score
0.002
Published
2022-06-07
Sensitive information exposure in Sign-in log in Samsung Account prior to version 13.2.00.6 allows attackers to get an user email or phone number without permission.
CVSS Score
4.0
EPSS Score
0.002
Published
2022-06-07
Unprotected activities in Voice Note prior to version 21.3.51.11 allows attackers to record voice without user interaction. The patch adds proper permission for vulnerable activities.
CVSS Score
6.2
EPSS Score
0.001
Published
2022-05-03
Improper authentication in Link to Windows Service prior to version 2.3.04.1 allows attacker to lock the device. The patch adds proper caller signature check logic.
CVSS Score
4.0
EPSS Score
0.001
Published
2022-05-03
Improper input validation vulnerability in InstallAgent in Galaxy Store prior to version 4.5.41.8 allows attacker to overwrite files stored in a specific path. The patch adds proper protection to prevent overwrite to existing files.
CVSS Score
6.2
EPSS Score
0.001
Published
2022-05-03
DLL hijacking vulnerability in Gear IconX PC Manager prior to version 2.1.220405.51 allows attacker to execute arbitrary code. The patch adds proper absolute path to prevent dll hijacking.
CVSS Score
6.2
EPSS Score
0.001
Published
2022-05-03
Given the TEE is compromised and controlled by the attacker, improper state maintenance in StrongBox allows attackers to change Android ROT during device boot cycle after compromising TEE. The patch is applied in Galaxy S22 to prevent change of Android ROT after first initialization at boot time.
CVSS Score
4.4
EPSS Score
0.001
Published
2022-05-03
Improper access control vulnerability in FactoryCamera prior to version 2.1.96 allows attacker to access the file with system privilege.
CVSS Score
7.7
EPSS Score
0.0
Published
2022-04-11
Improper authentication vulnerability in SecretMode in Samsung Internet prior to version 16.2.1 allows attackers to access bookmark tab without proper credentials.
CVSS Score
3.3
EPSS Score
0.002
Published
2022-04-11


Contact Us

Shodan ® - All rights reserved