Severity
3.3LOW
EPSS
0.1%
top 80.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 9
Latest updateSep 10

Description

Exposure of Sensitive Information in FaqSymptomCardViewModel in Samsung Members prior to versions 4.3.00.11 in Global and 14.0.02.4 in China allows local attackers to access device identification via log.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:NExploitability: 1.3 | Impact: 1.4

Affected Packages2 packages

NVDsamsung/samsung_members< 4.3.00.11+1
CVEListV5samsung_mobile/samsung_membersunspecified4.3.00.11 in Global and 14.0.02.4 in China

🔴Vulnerability Details

2
GHSA
GHSA-hq52-w3gp-7vw8: Exposure of Sensitive Information in FaqSymptomCardViewModel in Samsung Members prior to versions 42022-09-10
CVEList
CVE-2022-36877: Exposure of Sensitive Information in FaqSymptomCardViewModel in Samsung Members prior to versions 42022-09-09
CVE-2022-36877 (LOW CVSS 3.3) | Exposure of Sensitive Information i | cvebase.io