Vulnerabilities > CVE-2022-30746 - Missing Authorization vulnerability in Samsung Smartthings 1.7.73.22

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
samsung
CWE-862

Summary

Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely using javascript interface API.

Vulnerable Configurations

Part Description Count
Application
Samsung
2

Common Weakness Enumeration (CWE)