Improper Access Control in GearManagerStub Affects Samsung's Smart Devices
CVE-2023-21490
7.1HIGH
Summary
The GearManagerStub component prior to the SMR May-2023 Release 1 is susceptible to improper access control. This vulnerability enables a local attacker to delete applications installed by watchmanager, potentially compromising the functionality of the device and impacting user experience. It is essential for users to update their devices to the latest version to mitigate this risk and enhance security.
Affected Version(s)
Samsung Mobile Devices Android 11, 12, 13
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved