Vulnerabilities > Samsung > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-03-16 CVE-2023-21453 Improper Input Validation vulnerability in Samsung Android 13.0
Improper input validation vulnerability in SoftSim TA prior to SMR Mar-2023 Release 1 allows local attackers access to protected data.
local
low complexity
samsung CWE-20
5.5
2023-03-16 CVE-2023-21456 Path Traversal vulnerability in Samsung Android 11.0/12.0/13.0
Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uid.
local
low complexity
samsung CWE-22
5.5
2023-03-16 CVE-2023-21460 Improper Authentication vulnerability in Samsung Android 11.0/12.0/13.0
Improper authentication in SecSettings prior to SMR Mar-2023 Release 1 allows attacker to reset the setting.
local
low complexity
samsung CWE-287
4.4
2023-03-16 CVE-2023-21461 Unspecified vulnerability in Samsung Android 11.0/12.0/13.0
Improper authorization vulnerability in AutoPowerOnOffConfirmDialog in Settings prior to SMR Mar-2023 Release 1 allows local attacker to turn device off via unprotected activity.
local
low complexity
samsung
5.5
2023-03-16 CVE-2023-21465 Unspecified vulnerability in Samsung Bixbytouch
Improper access control vulnerability in BixbyTouch prior to version 3.2.02.5 in China models allows untrusted applications access local files.
local
low complexity
samsung
5.5
2023-02-09 CVE-2023-21422 Incorrect Authorization vulnerability in Samsung Android 11.0/12.0
Improper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attackers to set custom DNS server without permission via binding WifiService.
local
low complexity
samsung CWE-863
5.5
2023-02-09 CVE-2023-21423 Incorrect Authorization vulnerability in Samsung Android 12.0/13.0
Improper authorization vulnerability in ChnFileShareKit prior to SMR Jan-2023 Release 1 allows attacker to control BLE advertising without permission using unprotected action.
local
low complexity
samsung CWE-863
5.5
2023-02-09 CVE-2023-21425 Improper Authentication vulnerability in Samsung Android 10.0/11.0
Improper access control vulnerability in telecom application prior to SMR JAN-2023 Release 1 allows local attackers to get sensitive information.
local
low complexity
samsung CWE-287
5.5
2023-02-09 CVE-2023-21426 Use of Hard-coded Credentials vulnerability in Samsung Android 10.0
Hardcoded AES key to encrypt cardemulation PINs in NFC prior to SMR Jan-2023 Release 1 allows attackers to access cardemulation PIN.
local
low complexity
samsung CWE-798
5.5
2023-02-09 CVE-2023-21427 Unspecified vulnerability in Samsung Android 11.0/12.0
Improper access control vulnerability in NfcTile prior to SMR Jan-2023 Release 1 allows to attacker to use NFC without user recognition.
low complexity
samsung
6.5