Lucene search

K
cve[email protected]CVE-2022-36876
HistorySep 09, 2022 - 3:15 p.m.

CVE-2022-36876

2022-09-0915:15:13
CWE-285
web.nvd.nist.gov
24
6
cve-2022-36876
upi payment
samsung pass
authentication
physical attack

2.4 Low

CVSS3

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

3.9 Low

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

18.1%

Improper authorization in UPI payment in Samsung Pass prior to version 4.0.04.10 allows physical attackers to access account list without authentication.

Affected configurations

NVD
Node
samsungsamsung_passRange<4.0.04.10android

CNA Affected

[
  {
    "product": "Samsung Pass",
    "vendor": "Samsung Mobile",
    "versions": [
      {
        "lessThan": "4.0.04.10",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

2.4 Low

CVSS3

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

3.9 Low

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

18.1%

Related for CVE-2022-36876