Improper Access Control in Knox Enrollment Service by Samsung
CVE-2023-21495
5.5MEDIUM
Summary
An improper access control vulnerability exists in Knox Enrollment Service which allows an attacker to install the KSP app on a device where device administration is enabled. This flaw, if exploited, could lead to unauthorized access and potential misuse of the KSP functionalities, emphasizing the need for timely updates and security assessments.
Affected Version(s)
Samsung Mobile Devices Android 11, 12, 13
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved