Lucene search

K
cvelistSamsung MobileCVELIST:CVE-2022-24929
HistoryMar 08, 2022 - 1:46 p.m.

CVE-2022-24929

2022-03-0813:46:21
CWE-926
Samsung Mobile
www.cve.org

4.1 Medium

CVSS3

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

4.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

12.6%

Unprotected Activity in AppLock prior to SMR Mar-2022 Release 1 allows attacker to change the list of locked app without authentication.

CNA Affected

[
  {
    "product": "Samsung Mobile Devices",
    "vendor": "Samsung Mobile",
    "versions": [
      {
        "lessThan": "SMR Mar-2022 Release 1 ",
        "status": "affected",
        "version": "Q(10), R(11), S(12)",
        "versionType": "custom"
      }
    ]
  }
]

4.1 Medium

CVSS3

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

4.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

12.6%

Related for CVELIST:CVE-2022-24929