Improper Access Control in Samsung Pass Affects User Data Security
CVE-2022-36851

3.9LOW

Key Information:

Vendor
Samsung
Vendor
CVE Published:
9 September 2022

Summary

An improper access control vulnerability exists in Samsung Pass, prior to version 4.0.03.1, which can be exploited by physical attackers. This flaw allows unauthorized access to sensitive data stored in Samsung Pass when the device is in a specific unlocked state. Users utilizing affected versions are at an increased risk of data exposure, highlighting the importance of updating to the latest version to maintain security and protect personal information.

Affected Version(s)

Samsung pass < 4.0.03.1

References

CVSS V3.1

Score:
3.9
Severity:
LOW
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.