CVE-2023-42578

MEDIUM

Samsung Cloud < 5.2.00.7 - Unauthenticated Location Information Disclosure

Title source: llm
STIX 2.1

Description

Improper handling of insufficient permissions or privileges vulnerability in Samsung Data Store prior to version 5.2.00.7 allows remote attackers to access location information without permission.

References (1)

Core 1

Scores

CVSS v3 6.5
EPSS 0.0067
EPSS Percentile 46.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Details

CWE
CWE-755
Status published
Products (1)
samsung/cloud < 5.2.00.7
Published Dec 05, 2023
Tracked Since Feb 18, 2026