CVE-2022-23996Improper Access Control in Samsung Wear OS

Severity
3.3LOWNVD
CNA4.0
EPSS
0.2%
top 59.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 11
Latest updateFeb 12

Description

Unprotected component vulnerability in StTheaterModeReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to enable bedtime mode without a proper permission.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages2 packages

NVDsamsung/wear_os< 3.0
CVEListV5samsung_mobile/samsung_wearable_devicesWear OS 3.0Firmware update Feb-2022 Release

🔴Vulnerability Details

2
GHSA
GHSA-6x8m-f958-q43m: Unprotected component vulnerability in StTheaterModeReceiver in Wear OS 32022-02-12
CVEList
CVE-2022-23996: Unprotected component vulnerability in StTheaterModeReceiver in Wear OS 32022-02-11
CVE-2022-23996 — Improper Access Control in Samsung | cvebase