Path Traversal Vulnerability in Samsung Flow Before Version 4.8.07.4
CVE-2022-28543

4MEDIUM

Key Information:

Vendor
Samsung
Vendor
CVE Published:
11 April 2022

Summary

A path traversal vulnerability exists in Samsung Flow that allows local attackers to access and read arbitrary files on the system with the same permissions as the application, potentially exposing sensitive information. This flaw affects versions of Samsung Flow prior to 4.8.07.4, posing a risk to users who have not updated their software.

Affected Version(s)

Samsung Flow - < 4.8.07.4

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.