Improper Access Control in SmartThings by Samsung
CVE-2022-39869
4MEDIUM
What is CVE-2022-39869?
An improper access control vulnerability located in the cloudNotificationManager.java of Samsung's SmartThings, prior to version 1.7.89.0, allows unauthorized users to exploit the REMOVE_PERSISTENT_BANNER broadcast. This exploitation can potentially expose sensitive information, placing users at risk. Timely updates and patches are essential for maintaining system integrity.
Affected Version(s)
SmartThings < 1.7.89.0