Vulnerabilities > Samsung

DATE CVE VULNERABILITY TITLE RISK
2022-10-07 CVE-2022-39866 Unspecified vulnerability in Samsung Smartthings 1.7.73.22/1.7.85.12/1.7.85.25
Improper access control vulnerability in RegisteredEventMediator.kt SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast.
network
low complexity
samsung
7.5
2022-10-07 CVE-2022-39867 Unspecified vulnerability in Samsung Smartthings 1.7.73.22/1.7.85.12/1.7.85.25
Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via SHOW_PERSISTENT_BANNER broadcast.
network
low complexity
samsung
7.5
2022-10-07 CVE-2022-39868 Unspecified vulnerability in Samsung Smartthings 1.7.73.22/1.7.85.12/1.7.85.25
Improper access control vulnerability in GedSamsungAccount.kt SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast.
network
low complexity
samsung
7.5
2022-10-07 CVE-2022-39869 Exposure of Resource to Wrong Sphere vulnerability in Samsung Smartthings 1.7.73.22/1.7.85.12/1.7.85.25
Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via REMOVE_PERSISTENT_BANNER broadcast.
network
low complexity
samsung CWE-668
7.5
2022-10-07 CVE-2022-39870 Exposure of Resource to Wrong Sphere vulnerability in Samsung Smartthings 1.7.73.22/1.7.85.12/1.7.85.25
Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via PUSH_MESSAGE_RECEIVED broadcast.
network
low complexity
samsung CWE-668
7.5
2022-10-07 CVE-2022-39871 Exposure of Resource to Wrong Sphere vulnerability in Samsung Smartthings 1.7.73.22/1.7.85.12/1.7.85.25
Improper access control vulnerability cloudNotificationManager.java in SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcasts.
network
low complexity
samsung CWE-668
7.5
2022-10-07 CVE-2022-39872 Improper Handling of Exceptional Conditions vulnerability in Samsung Sharelive
Improper restriction of broadcasting Intent in ShareLive prior to version 13.2.03.5 leaks MAC address of the connected Bluetooth device.
local
low complexity
samsung CWE-755
3.3
2022-10-07 CVE-2022-39873 Unspecified vulnerability in Samsung Internet
Improper authorization vulnerability in Samsung Internet prior to version 18.0.4.14 allows physical attackers to add bookmarks in secret mode without user authentication.
low complexity
samsung
4.6
2022-10-07 CVE-2022-39874 Information Exposure Through Log Files vulnerability in Samsung Account
Sensitive log information leakage vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthorized logout.
local
low complexity
samsung CWE-532
5.5
2022-10-07 CVE-2022-39875 Unspecified vulnerability in Samsung Account
Improper component protection vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthorized logout.
local
low complexity
samsung
4.4