CVE-2022-36874

MEDIUM

Samsung Galaxy Watch Plugin - Improper Exception Handling

Title source: rule

Description

Improper Handling of Insufficient Permissions or Privileges vulnerability in Waterplugin prior to 2.2.11.22040751 allows attacker to access device IMEI and Serial number.

Scores

CVSS v3 5.9
EPSS 0.0004
EPSS Percentile 13.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Classification

CWE
CWE-755 CWE-280
Status published

Affected Products (1)

samsung/galaxy_watch_plugin < 2.2.11.22040751

Timeline

Published Sep 09, 2022
Tracked Since Feb 18, 2026