Samsung Mobile Vulnerabilities and Affected Products
Vulnerabilities associated with Smart Things.
Products
Clear product- Samsung Mobile Devices832 vulnerabilities
- Samsung Notes60 vulnerabilities
- Galaxy Store29 vulnerabilities
- Samsung Account28 vulnerabilities
- Samsung Internet27 vulnerabilities
- Smart Switch17 vulnerabilities
- Samsung Pass16 vulnerabilities
- Samsung Health15 vulnerabilities
- SmartThings15 vulnerabilities
- Samsung Members14 vulnerabilities
- Samsung Email13 vulnerabilities
- Samsung Flow8 vulnerabilities
- Blockchain Keystore7 vulnerabilities
- Samsung Blockchain Keystore7 vulnerabilities
- Samsung Pay6 vulnerabilities
- Smart Things6 vulnerabilities
- Tizen wearable devices6 vulnerabilities
- Charm by Samsung5 vulnerabilities
- Galaxy Wearable5 vulnerabilities
- Group Sharing5 vulnerabilities
- S Assistant5 vulnerabilities
- Samsung Assistant5 vulnerabilities
- Samsung Cloud5 vulnerabilities
- Samsung Gallery5 vulnerabilities
- Samsung Voice Recorder5 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-21432MEDIUM | Improper access control vulnerabilities in Smart Things prior to 1.7.93 allows to attacker to invite others without authorization of the owner. CWE-285Feb 9, 2023 | CVSS4.2v3.1 | EPSS0.155% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Improper access control vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to add arbitrary smart devices by bypassing login activity. CWE-287Jun 7, 2022 | CVSS3.3v3.1 | EPSS0.18% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2022-30747MEDIUM | PendingIntent hijacking vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to access files without permission via implicit Intent. CWE-276Jun 7, 2022 | CVSS5.5v3.1 | EPSS0.191% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-30746HIGH | Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely using javascript interface API. | CVSS7.5v3.1 | EPSS0.844% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause local file inclusion in webview. | CVSS-v3.1 | EPSS0.794% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause arbitrary webpage loading in webview. | CVSS-v3.1 | EPSS0.814% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |