Lucene search

K
cve[email protected]CVE-2023-42545
HistoryNov 07, 2023 - 8:15 a.m.

CVE-2023-42545

2023-11-0708:15:21
web.nvd.nist.gov
9
cve-2023-42545
implicit intent
sensitive communication
vulnerability
phone
android 11
android 12
android 13
location data

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

30.0%

Use of implicit intent for sensitive communication vulnerability in Phone prior to versions 12.7.20.12 in Android 11, 13.1.48, 13.5.28 in Android 12, and 14.7.38 in Android 13 allows attackers to access location data.

Affected configurations

NVD
Node
samsungphoneRange<12.7.20.12
AND
samsungandroidMatch11.0-
Node
samsungphoneRange<13.1.48
OR
samsungphoneRange13.5.013.5.28
AND
samsungandroidMatch12.0-
Node
samsungphoneRange<14.7.38
AND
samsungandroidMatch13.0-
CPENameOperatorVersion
samsung:phonesamsung phonelt12.7.20.12

CNA Affected

[
  {
    "vendor": "Samsung Mobile",
    "product": "Phone",
    "versions": [
      {
        "status": "unaffected",
        "version": "12.7.20.12 in Android 11, 13.1.48, 13.5.28 in Android 12, and 14.7.38 in Android 13"
      }
    ],
    "defaultStatus": "affected"
  }
]

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

30.0%

Related for CVE-2023-42545