Improper Access Control in GearManagerStub Affects Samsung's Smart Devices
CVE-2023-21490

7.1HIGH

Key Information:

Vendor
Samsung
Vendor
CVE Published:
4 May 2023

Summary

The GearManagerStub component prior to the SMR May-2023 Release 1 is susceptible to improper access control. This vulnerability enables a local attacker to delete applications installed by watchmanager, potentially compromising the functionality of the device and impacting user experience. It is essential for users to update their devices to the latest version to mitigate this risk and enhance security.

Affected Version(s)

Samsung Mobile Devices Android 11, 12, 13

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.