Sensitive Information Exposure in SReminder by Samsung
CVE-2022-39876
5.9MEDIUM
Summary
The SReminder application developed by Samsung is vulnerable to a flaw that allows the insertion of sensitive information into logs. Versions prior to 8.2.01.13 exhibit this vulnerability, which potentially enables an attacker to gain unauthorized access to device IMEI numbers, a critical piece of mobile device information. This could lead to various security risks, including tracking and device impersonation. Users are encouraged to update to the latest version to mitigate this risk and enhance their device security.
Affected Version(s)
Reminder < 8.2.01.13
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved