Improper Access Control in Smart Things by Samsung
CVE-2022-30749

3.3LOW

Key Information:

Vendor
Samsung
Vendor
CVE Published:
7 June 2022

Summary

An improper access control vulnerability in Samsung's Smart Things application prior to version 1.7.85.25 allows local attackers to bypass login mechanisms and add any arbitrary smart device to the network. This flaw poses significant risks to device security and could lead to unauthorized access and control over smart home systems.

Affected Version(s)

Smart Things < 1.7.85.25

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.