5.4
CVE-2023-30736
- EPSS 0.24%
- Veröffentlicht 04.10.2023 04:15:13
- Zuletzt bearbeitet 21.11.2024 08:00:48
- Erkennungen
Improper authorization in PushMsgReceiver of Samsung Assistant prior to version 8.7.00.1 allows attacker to execute javascript interface. To trigger this vulnerability, user interaction is required.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Samsung ≫ Samsung Assistant Version < 8.7.00.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.149 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
|
| mobile.security@samsung.com | 4.4 | 1.8 | 2.5 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
|
https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=10