CVE-2022-27841

Severity
4.3MEDIUM
EPSS
0.1%
top 80.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 11
Latest updateApr 12

Description

Improper exception handling in Samsung Pass prior to version 3.7.07.5 allows physical attacker to view the screen that is previously running without authentication

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 0.7 | Impact: 3.6

Affected Packages2 packages

NVDsamsung/samsung_pass< 3.7.07.5
CVEListV5samsung_mobile/samsung_pass-3.0.07.5

🔴Vulnerability Details

2
GHSA
GHSA-xxq8-w68p-wqxp: Improper exception handling in Samsung Pass prior to version 32022-04-12
CVEList
CVE-2022-27841: Improper exception handling in Samsung Pass prior to version 32022-04-11