6.5

CVE-2022-36871

Pending Intent hijacking vulnerability in NotiCenterUtils in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Samsung ≫ Samsung Pay SwPlatform android Version < 5.1.47
Samsung ≫ Samsung Pay Kr SwPlatform android Version < 5.0.63
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.064
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2 4
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
mobile.security@samsung.com 5 1.8 2.7
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:L
CWE-285 Improper Authorization

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

https://security.samsungmobile.com/serviceWeb.smsb?year=2022&month=09
Vendor Advisory