Lucene search

K
cve[email protected]CVE-2023-42553
HistoryNov 07, 2023 - 8:15 a.m.

CVE-2023-42553

2023-11-0708:15:23
web.nvd.nist.gov
8
cve-2023-42553
improper authorization verification
samsung email
vulnerability
nvd
sandbox data
email

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

5.2 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

16.1%

Improper authorization verification vulnerability in Samsung Email prior to version 6.1.90.4 allows attackers to read sandbox data of email.

Affected configurations

NVD
Node
samsungemailRange<6.1.90.4
CPENameOperatorVersion
samsung:emailsamsung emaillt6.1.90.4

CNA Affected

[
  {
    "vendor": "Samsung Mobile",
    "product": "Samsung Email",
    "versions": [
      {
        "status": "unaffected",
        "version": "6.1.90.4"
      }
    ],
    "defaultStatus": "affected"
  }
]

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

5.2 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

16.1%

Related for CVE-2023-42553