CVE-2023-42554

Severity
6.8MEDIUM
EPSS
0.0%
top 90.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 7
Latest updateNov 15

Description

Improper Authentication vulnerabiity in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication.

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:NExploitability: 0.2 | Impact: 5.2

Affected Packages1 packages

NVDsamsung/pass< 4.3.00.17

🔴Vulnerability Details

2
GHSA
GHSA-v5h3-wx8w-wpmx: Improper Authentication vulnerabiity in Samsung Pass prior to version 42023-11-15
CVEList
CVE-2023-42554: Improper Authentication vulnerabiity in Samsung Pass prior to version 42023-11-07
CVE-2023-42554 (MEDIUM CVSS 6.8) | Improper Authentication vulnerabiit | cvebase.io