Lucene search

K
cvelistSamsung MobileCVELIST:CVE-2023-30723
HistorySep 06, 2023 - 3:12 a.m.

CVE-2023-30723

2023-09-0603:12:10
Samsung Mobile
www.cve.org
1
improper input validation
arbitrary file write
samsung health privilege

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

9.7 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

31.0%

Improper input validation vulnerability in Samsung Health prior to version 6.24.2.011 allows attackers to write arbitrary file with Samsung Health privilege.

CNA Affected

[
  {
    "vendor": "Samsung Mobile",
    "product": "Samsung Health",
    "versions": [
      {
        "status": "unaffected",
        "version": "6.24.2.011"
      }
    ],
    "defaultStatus": "affected"
  }
]

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

9.7 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

31.0%

Related for CVELIST:CVE-2023-30723