Sensitive Information Exposure in Samsung Members App
CVE-2022-36877

2.8LOW

Key Information:

Vendor
Samsung
Vendor
CVE Published:
9 September 2022

Summary

The Samsung Members application prior to specified versions is susceptible to a vulnerability that allows local attackers to exploit the FaqSymptomCardViewModel component. This flaw can result in the unintentional exposure of sensitive device identification information through application logs, potentially threatening user privacy and security. It is crucial for users and administrators to update to the latest versions to mitigate this risk.

Affected Version(s)

Samsung Members < 4.3.00.11 in Global and 14.0.02.4 in China

References

CVSS V3.1

Score:
2.8
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.