5.4
CVE-2023-30736
- EPSS 0.1%
- Veröffentlicht 04.10.2023 04:15:13
- Zuletzt bearbeitet 21.11.2024 08:00:48
- Quelle mobile.security@samsung.com
- CVE-Watchlists
- Unerledigt
Improper authorization in PushMsgReceiver of Samsung Assistant prior to version 8.7.00.1 allows attacker to execute javascript interface. To trigger this vulnerability, user interaction is required.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Samsung ≫ Samsung Assistant Version < 8.7.00.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.1% | 0.275 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
|
| mobile.security@samsung.com | 4.4 | 1.8 | 2.5 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
|