Lucene search

K
cvelistSamsungMobileCVELIST:CVE-2024-20803
HistoryJan 04, 2024 - 1:10 a.m.

CVE-2024-20803

2024-01-0401:10:11
SamsungMobile
www.cve.org
bluetooth
authentication
vulnerability
remote attackers
user interaction

6.8 Medium

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

6.9 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

30.7%

Improper authentication vulnerability in Bluetooth pairing process prior to SMR Jan-2024 Release 1 allows remote attackers to establish pairing process without user interaction.

CNA Affected

[
  {
    "vendor": "Samsung Mobile",
    "product": "Samsung Mobile Devices",
    "versions": [
      {
        "status": "unaffected",
        "version": "SMR Jan-2024 Release in Android 11, 12, 13, 14"
      }
    ],
    "defaultStatus": "affected"
  }
]

6.8 Medium

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

6.9 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

30.7%

Related for CVELIST:CVE-2024-20803