Improper Access Control in Samsung Pass Affects User Data Security
CVE-2023-30676

4.6MEDIUM

Key Information:

Vendor
Samsung
Vendor
CVE Published:
6 July 2023

Summary

An improper access control vulnerability has been identified in Samsung Pass that allows physical attackers to obtain sensitive data. This security flaw exists in versions prior to 4.2.03.1, exposing users to potential unauthorized access. It is crucial for users of Samsung Pass to ensure their application is updated to mitigate risks associated with this vulnerability.

Affected Version(s)

Samsung Pass 4.2.03.1

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.