CVE-2022-36877

LOW

Samsung Members < 4.3.00.11 - Information Disclosure

Title source: rule
STIX 2.1

Description

Exposure of Sensitive Information in FaqSymptomCardViewModel in Samsung Members prior to versions 4.3.00.11 in Global and 14.0.02.4 in China allows local attackers to access device identification via log.

References (1)

Core 1
Core References

Scores

CVSS v3 2.8
EPSS 0.0006
EPSS Percentile 18.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

Details

CWE
CWE-532 CWE-200
Status published
Products (2)
samsung/samsung_members < 14.0.02.4
samsung/samsung_members < 4.3.00.11
Published Sep 09, 2022
Tracked Since Feb 18, 2026