4.2
CVE-2023-21462
- EPSS 0.04%
- Published 16.03.2023 21:15:12
- Last modified 21.11.2024 07:42:55
- Source mobile.security@samsung.com
- Teams watchlist Login
- Open Login
The sensitive information exposure vulnerability in Quick Share Agent prior to versions 3.5.14.18 in Android 12 and 3.5.16.20 in Android 13 allows to local attacker to access MAC address without related permission.
Data is provided by the National Vulnerability Database (NVD)
Samsung ≫ Quick Share Version < 3.5.14.18
Samsung ≫ Quick Share Version < 3.5.16.20
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.04% | 0.085 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 3.3 | 1.8 | 1.4 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
mobile.security@samsung.com | 4.2 | 1.1 | 2.7 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
|
CWE-215 Insertion of Sensitive Information Into Debugging Code
The product inserts sensitive information into debugging code, which could expose this information if the debugging code is not disabled in production.