CVE-2024-32670

HIGH

Samsung Galaxy SmartTag2 <0.20.04 - Info Disclosure

Title source: llm
STIX 2.1

Description

Exposure of Sensitive Information to an Unauthorized Actor in Samsung Galaxy SmartTag2 prior to 0.20.04 allows attackes to potentially identify the tag's location by scanning the BLE adversting.

References (1)

Core 1
Core References

Scores

CVSS v4 7.0
EPSS 0.0015
EPSS Percentile 34.7%
CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
Samsung/Galaxy SmartTag2 0.20.04
Published Jul 10, 2024
Tracked Since Feb 18, 2026