CVE-2020-13838

LOW

Samsung Android P(9.0) and Q(10.0) - Unauthenticated Access to Quick Panel and Notifications via DeX Lockscreen

Title source: llm
STIX 2.1

Description

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. The DeX Lockscreen feature does not block access to Quick Panel and notifications. The Samsung ID is SVE-2020-17187 (June 2020).

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://security.samsungmobile.com/securityUpdate.smsb

Scores

CVSS v3 3.5
EPSS 0.0013
EPSS Percentile 3.0%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-306
Status published
Products (2)
google/android 9.0
google/android 10.0
Published Jun 04, 2020
Tracked Since Feb 18, 2026