CVE-2022-39871

MEDIUM

Samsung Smartthings < 1.7.89.0 - Improper Access Control

Title source: rule

Description

Improper access control vulnerability cloudNotificationManager.java in SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcasts.

Scores

CVSS v3 4.0
EPSS 0.0018
EPSS Percentile 38.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-284 CWE-668
Status published

Affected Products (1)

samsung/smartthings < 1.7.89.0

Timeline

Published Oct 07, 2022
Tracked Since Feb 18, 2026