3.3

CVE-2023-21462

The sensitive information exposure vulnerability in Quick Share Agent prior to versions 3.5.14.18 in Android 12 and 3.5.16.20 in Android 13 allows to local attacker to access MAC address without related permission.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Samsung ≫ Quick Share Version < 3.5.14.18
   Google ≫ Android Version 12.0
Samsung ≫ Quick Share Version < 3.5.16.20
   Google ≫ Android Version 13.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.052
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 3.3 1.8 1.4
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
mobile.security@samsung.com 4.2 1.1 2.7
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CWE-215 Insertion of Sensitive Information Into Debugging Code

The product inserts sensitive information into debugging code, which could expose this information if the debugging code is not disabled in production.

https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=03
Vendor Advisory