CVE-2022-27836Improper Access Control in Mobile Devices

Severity
7.8HIGHNVD
CNA8.4
EPSS
0.0%
top 98.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 11
Latest updateApr 12

Description

Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr-2022 Release 1 allow local attackers to access arbitrary system files without a proper permission. The patch adds proper validation logic to prevent arbitrary files access.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5samsung_mobile/samsung_mobile_devicesS(12)SMR Apr-2022 Release 1
NVDgoogle/android12.0

🔴Vulnerability Details

2
GHSA
GHSA-557f-9chj-3w83: Improper access control and path traversal vulnerability in StroageManager and StroageManagerService prior to SMR Apr-2022 Release 1 allow local attac2022-04-12
CVEList
CVE-2022-27836: Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr-2022 Release 1 allow local at2022-04-11
CVE-2022-27836 — Improper Access Control | cvebase