Lucene search

K
cveSamsung MobileCVE-2022-39893
HistoryNov 09, 2022 - 10:15 p.m.

CVE-2022-39893

2022-11-0922:15:18
CWE-532
Samsung Mobile
web.nvd.nist.gov
33
4
cve-2022-39893
sensitive information exposure
fmmbasemodel
galaxy buds pro manage
vulnerability
nvd
security
device log

CVSS3

3.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

3.8

Confidence

High

EPSS

0

Percentile

5.1%

Sensitive information exposure vulnerability in FmmBaseModel in Galaxy Buds Pro Manage prior to version 4.1.22092751 allows local attackers with log access permission to get device identifier data through device log.

Affected configurations

Nvd
Node
samsunggalaxy_buds_pro_manageRange<4.1.22092751
VendorProductVersionCPE
samsunggalaxy_buds_pro_manage*cpe:2.3:a:samsung:galaxy_buds_pro_manage:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Samsung Mobile",
    "product": "Galaxy Buds Pro Manager",
    "versions": [
      {
        "version": "unspecified",
        "status": "affected",
        "lessThan": "4.1.22092751",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS3

3.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

3.8

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVE-2022-39893