Lucene search

K
cvelistSamsung MobileCVELIST:CVE-2023-21445
HistoryFeb 09, 2023 - 12:00 a.m.

CVE-2023-21445

2023-02-0900:00:00
CWE-284
Samsung Mobile
www.cve.org
6
access control
myfiles
android.

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

AI Score

7.6

Confidence

High

EPSS

0.001

Percentile

24.6%

Improper access control vulnerability in MyFiles prior to versions 12.2.09 in Android R(11), 13.1.03.501 in Android S(12) and 14.1.00.422 in Android T(13) allows local attacker to write file with MyFiles privilege via implicit intent.

CNA Affected

[
  {
    "vendor": "Samsung Mobile",
    "product": "The patch adds proper access control to use explicit intent.",
    "versions": [
      {
        "version": "unspecified",
        "status": "affected",
        "lessThan": "12.2.09 in Android R(11), 13.1.03.501 in Android S(12) and 14.1.00.422 in Android T(13)",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

AI Score

7.6

Confidence

High

EPSS

0.001

Percentile

24.6%

Related for CVELIST:CVE-2023-21445