5.4
CVE-2023-30736
- EPSS 0.11%
- Published 04.10.2023 04:15:13
- Last modified 21.11.2024 08:00:48
- Source mobile.security@samsung.com
- Teams watchlist Login
- Open Login
Improper authorization in PushMsgReceiver of Samsung Assistant prior to version 8.7.00.1 allows attacker to execute javascript interface. To trigger this vulnerability, user interaction is required.
Data is provided by the National Vulnerability Database (NVD)
Samsung ≫ Samsung Assistant Version < 8.7.00.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.11% | 0.3 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
|
mobile.security@samsung.com | 4.4 | 1.8 | 2.5 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
|