Improper Authorization Vulnerability in Samsung Keyboard
CVE-2024-20871

4.9MEDIUM

Key Information:

Vendor
Samsung
Vendor
CVE Published:
7 May 2024

Summary

An improper authorization vulnerability has been identified in Samsung Keyboard versions prior to One UI 5.1.1. This vulnerability allows physical attackers to exploit the device, enabling them to partially bypass factory reset protection mechanisms. As a result, unauthorized access to the device's data and functionality may occur, posing potential risks to user privacy and security.

Affected Version(s)

Samsung Keyboard One UI 5.1.1

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.