CVE-2022-22287Improper Input Validation in Mobile Samsung Email

Severity
4.6MEDIUMNVD
CNA3.9
EPSS
0.1%
top 79.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 10
Latest updateJan 11

Description

Abitrary file access vulnerability in Samsung Email prior to 6.1.60.16 allows attacker to read isolated data in sandbox.

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 0.9 | Impact: 3.6

Affected Packages2 packages

NVDsamsung/samsung_email< 6.1.60.16
CVEListV5samsung_mobile/samsung_email-6.1.60.16

🔴Vulnerability Details

2
GHSA
GHSA-vpwc-jhj4-x9q2: Abitrary file access vulnerability in Samsung Email prior to 62022-01-11
CVEList
CVE-2022-22287: Abitrary file access vulnerability in Samsung Email prior to 62022-01-07
CVE-2022-22287 — Improper Input Validation | cvebase