CVE-2022-28778

MEDIUM

Samsung Security Supporter <1.2.40.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Improper access control vulnerability in Samsung Security Supporter prior to version 1.2.40.0 allows attacker to set the arbitrary folder as Secret Folder without Samsung Security Supporter permission

References (1)

Core 1
Core References

Scores

CVSS v3 4.4
EPSS 0.0006
EPSS Percentile 17.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Details

CWE
CWE-284
Status published
Products (1)
samsung/samsung_security_supporter < 1.2.40.0
Published Apr 11, 2022
Tracked Since Feb 18, 2026