Lucene search

K
cveSamsung MobileCVE-2022-36838
HistoryAug 05, 2022 - 4:15 p.m.

CVE-2022-36838

2022-08-0516:15:15
CWE-285
Samsung Mobile
web.nvd.nist.gov
43
5
cve-2022-36838
vulnerability
galaxy wearable
implicit intent hijacking
sensitive information disclosure
nvd

CVSS3

4.6

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

4.7

Confidence

High

EPSS

0.001

Percentile

23.7%

Implicit Intent hijacking vulnerability in Galaxy Wearable prior to version 2.2.50 allows attacker to get sensitive information.

Affected configurations

Nvd
Node
samsunggalaxy_wearableRange<2.2.50
VendorProductVersionCPE
samsunggalaxy_wearable*cpe:2.3:a:samsung:galaxy_wearable:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Galaxy Wearable",
    "vendor": "Samsung Mobile",
    "versions": [
      {
        "lessThan": "2.2.50",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS3

4.6

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

4.7

Confidence

High

EPSS

0.001

Percentile

23.7%

Related for CVE-2022-36838