5.7

CVE-2024-20840

Improper access control in Samsung Voice Recorder prior to versions 21.5.16.01 in Android 12 and Android 13, 21.4.51.02 in Android 14 allows physical attackers using hardware keyboard to use VoiceRecorder on the lock screen.

Data is provided by the National Vulnerability Database (NVD)
SamsungVoice Recorder Version < 21.5.16.01
   GoogleAndroid Version12.0
   GoogleAndroid Version13.0
SamsungVoice Recorder Version < 21.4.51.02
   GoogleAndroid Version14.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.101
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 2.4 0.9 1.4
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
mobile.security@samsung.com 5.7 0.5 5.2
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H