CVE-2024-20854

MEDIUM

Samsung Camera <14.0.01.06 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Improper handling of insufficient privileges vulnerability in Samsung Camera prior to versions 12.1.0.31 in Android 12, 13.1.02.07 in Android 13, and 14.0.01.06 in Android 14 allows local attackers to access image data.

References (1)

Core 1

Scores

CVSS v3 5.9
EPSS 0.0010
EPSS Percentile 27.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (1)
samsung/camera < 12.1.0.31
Published Apr 02, 2024
Tracked Since Feb 18, 2026