Improper Certificate Validation in Samsung Email
CVE-2023-30729

8.1HIGH

Key Information:

Vendor
Samsung
Vendor
CVE Published:
6 September 2023

Summary

Vulnerability in Samsung Email prior to version 6.1.82.0 allows remote attackers to perform man-in-the-middle attacks by exploiting improper certificate validation. This flaw can result in the interception of network traffic, potentially exposing sensitive user information. Users are advised to update their software to the latest version to mitigate this risk.

Affected Version(s)

Samsung Email 6.1.82.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.