Improper Authorization Vulnerability in Samsung Keyboard
CVE-2024-20871
4.9MEDIUM
Summary
An improper authorization vulnerability has been identified in Samsung Keyboard versions prior to One UI 5.1.1. This vulnerability allows physical attackers to exploit the device, enabling them to partially bypass factory reset protection mechanisms. As a result, unauthorized access to the device's data and functionality may occur, posing potential risks to user privacy and security.
Affected Version(s)
Samsung Keyboard One UI 5.1.1
References
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved