Lucene search

K
cve[email protected]CVE-2023-30729
HistorySep 06, 2023 - 4:15 a.m.

CVE-2023-30729

2023-09-0604:15:16
CWE-295
web.nvd.nist.gov
16
samsung email
cve-2023-30729
certificate validation
network traffic interception
nvd

8.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

7.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

33.6%

Improper Certificate Validation in Samsung Email prior to version 6.1.82.0 allows remote attacker to intercept the network traffic including sensitive information.

Affected configurations

NVD
Node
samsungemailRange<6.1.82.0
CPENameOperatorVersion
samsung:emailsamsung emaillt6.1.82.0

CNA Affected

[
  {
    "vendor": "Samsung Mobile",
    "product": "Samsung Email",
    "versions": [
      {
        "status": "unaffected",
        "version": "6.1.82.0"
      }
    ],
    "defaultStatus": "affected"
  }
]

8.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

7.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

33.6%

Related for CVE-2023-30729