Improper Access Control in Samsung Pass by Samsung
CVE-2022-39910

3.9LOW

Key Information:

Vendor
Samsung
Vendor
CVE Published:
8 December 2022

Summary

An improper access control vulnerability in Samsung Pass prior to version 4.0.06.7 allows physical attackers to gain unauthorized access to sensitive data stored within the application on an unlocked device. The flaw can be exploited during a specific state involving a pop-up view, posing a significant security risk to users who may inadvertently expose confidential information.

Affected Version(s)

Samsung Pass < 4.0.06.7

References

CVSS V3.1

Score:
3.9
Severity:
LOW
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.