CVE-2024-20851

MEDIUM

Samsung Data Store <5.3.00.4 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Improper access control vulnerability in Samsung Data Store prior to version 5.3.00.4 allows local attackers to launch arbitrary activity with Samsung Data Store privilege.

References (1)

Core 1

Scores

CVSS v3 4.4
EPSS 0.0007
EPSS Percentile 21.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (1)
samsung/cloud < 5.3.00.4
Published Apr 02, 2024
Tracked Since Feb 18, 2026