CVE-2023-21456Path Traversal in Mobile Devices

CWE-22Path Traversal3 documents3 sources
Severity
5.5MEDIUMNVD
CNA9.0
EPSS
0.1%
top 73.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 16

Description

Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uid.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5samsung_mobile/samsung_mobile_devicesAndroid 11, 12, 13SMR Mar-2023 Release 1
NVDsamsung/android11.0, 12.0, 13.0+2

🔴Vulnerability Details

2
GHSA
GHSA-qmcj-8g67-9633: Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uid2023-03-16
CVEList
CVE-2023-21456: Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uid2023-03-16
CVE-2023-21456 — Path Traversal in Mobile Devices | cvebase