Samsung Mobile Vulnerabilities and Affected Products
Vulnerabilities associated with Samsung Pass.
Products
Clear product- Samsung Mobile Devices832 vulnerabilities
- Samsung Notes60 vulnerabilities
- Galaxy Store29 vulnerabilities
- Samsung Account28 vulnerabilities
- Samsung Internet27 vulnerabilities
- Smart Switch17 vulnerabilities
- Samsung Pass16 vulnerabilities
- Samsung Health15 vulnerabilities
- SmartThings15 vulnerabilities
- Samsung Members14 vulnerabilities
- Samsung Email13 vulnerabilities
- Samsung Flow8 vulnerabilities
- Blockchain Keystore7 vulnerabilities
- Samsung Blockchain Keystore7 vulnerabilities
- Samsung Pay6 vulnerabilities
- Smart Things6 vulnerabilities
- Tizen wearable devices6 vulnerabilities
- Charm by Samsung5 vulnerabilities
- Galaxy Wearable5 vulnerabilities
- Group Sharing5 vulnerabilities
- S Assistant5 vulnerabilities
- Samsung Assistant5 vulnerabilities
- Samsung Cloud5 vulnerabilities
- Samsung Gallery5 vulnerabilities
- Samsung Voice Recorder5 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-21057MEDIUM | Generated title:Samsung Pass Out-of-Bounds WriteImproper input validation in Samsung Pass prior to version 5.2.10.3 allows local privileged attackers to write out-of-bounds memory. CWE-20Jul 10, 2026 | CVSS6.8v4.0 | EPSS0.116% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-49405MEDIUM | Improper authentication in Private Info in Samsung Pass in prior to version 4.4.04.7 allows physical attackers to access sensitive information in a specific scenario. CWE-287Nov 6, 2024 | CVSS5.3v3.1 | EPSS0.233% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-42576MEDIUM | Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication due to invalid exception handler. CWE-287Dec 5, 2023 | CVSS5.4v3.1 | EPSS0.38% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-42575MEDIUM | Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication due to invalid flag setting. | CVSS5.4v3.1 | EPSS0.38% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-42554MEDIUM | Improper Authentication vulnerabiity in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication. CWE-287Nov 7, 2023 | CVSS5.4v3.1 | EPSS0.34% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-30677MEDIUM | Improper access control vulnerability in Samsung Pass prior to version 4.2.03.1 allows physical attackers to access data of Samsung Pass on a certain state of an unlocked device. CWE-284Jul 6, 2023 | CVSS6.1v3.1 | EPSS0.25% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-30676MEDIUM | Improper access control vulnerability in Samsung Pass prior to version 4.2.03.1 allows physical attackers to access data of Samsung Pass. CWE-284Jul 6, 2023 | CVSS4.6v3.1 | EPSS0.25% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-30675MEDIUM | Improper authentication in Samsung Pass prior to version 4.2.03.1 allows local attacker to access stored account information when Samsung Wallet is not installed. CWE-287Jul 6, 2023 | CVSS6.2v3.1 | EPSS0.162% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-39911MEDIUM | Improper check or handling of exceptional conditions vulnerability in Samsung Pass prior to version 4.0.06.1 allows attacker to access Samsung Pass. CWE-703Dec 8, 2022 | CVSS4.8v3.1 | EPSS0.246% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Improper access control vulnerability in Samsung Pass prior to version 4.0.06.7 allow physical attackers to access data of Samsung Pass on a certain state of an unlocked device using pop-up view. CWE-284Dec 8, 2022 | CVSS3.9v3.1 | EPSS0.262% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Improper access control in Samsung Pass prior to version 4.0.05.1 allows attackers to unauthenticated access via keep open feature. CWE-287Nov 9, 2022 | CVSS3.6v3.1 | EPSS0.395% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Improper access control vulnerability in Samsung pass prior to version 4.0.03.1 allow physical attackers to access data of Samsung pass on a certain state of an unlocked device. CWE-284Sep 9, 2022 | CVSS3.9v3.1 | EPSS0.322% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Improper authorization in UPI payment in Samsung Pass prior to version 4.0.04.10 allows physical attackers to access account list without authentication. | CVSS1.8v3.1 | EPSS0.323% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2022-30730MEDIUM | Improper authorization in Samsung Pass prior to 1.0.00.33 allows physical attackers to acess account list without authentication. | CVSS4.6v3.1 | EPSS0.245% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-27841MEDIUM | Improper exception handling in Samsung Pass prior to version 3.7.07.5 allows physical attacker to view the screen that is previously running without authentication | CVSS4.3v3.1 | EPSS0.271% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Improper authentication in Samsung Pass prior to 3.0.02.4 allows to use app without authentication when lockscreen is unlocked. CWE-287Nov 5, 2021 | CVSS3.3v3.1 | EPSS0.571% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |