Path Traversal Vulnerability in Samsung Notes by Samsung Electronics
CVE-2022-36831

6.2MEDIUM

Key Information:

Vendor
Samsung
Vendor
CVE Published:
5 August 2022

Summary

A path traversal vulnerability in the UriFileUtils component of Samsung Notes allows unauthorized access to files within the application. Attackers could exploit this flaw to gain access to restricted file paths, thereby enabling the potential extraction of sensitive data without proper permissions. This vulnerability affects all versions prior to 4.3.14.39, necessitating users to update their applications to maintain security and data integrity.

Affected Version(s)

Samsung notes < 4.3.14.39

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.