Information Exposure in Watch Active2 Plugin by Samsung
CVE-2022-25829

1.9LOW

Key Information:

Vendor
Samsung
Vendor
CVE Published:
10 March 2022

Summary

The Watch Active2 Plugin from Samsung is vulnerable to information exposure, allowing attackers to potentially access log files containing sensitive WiFi access point passwords. This vulnerability affects versions prior to 2.2.08.22012751, highlighting the importance of keeping the plugin updated to safeguard against unauthorized data access.

Affected Version(s)

Watch Active2 PlugIn - < 2.2.08.22012751

References

CVSS V3.1

Score:
1.9
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.