Description
Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication due to invalid flag setting.
CVSS vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 0.9 | Impact: 5.9Attack Vector: Physical
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: High
Availability: High
Affected Packages1 packages
🔴Vulnerability Details
2GHSAGHSA-xf3p-q42r-rwgf: Improper Authentication vulnerability in Samsung Pass prior to version 4↗2023-12-05 ▶ CVEListCVE-2023-42575: Improper Authentication vulnerability in Samsung Pass prior to version 4↗2023-12-05 ▶ 📋Vendor Advisories
2OracleOracle Oracle Communications Applications Risk Matrix: Configuration (Java HTML Sanitizer) — CVE-2021-42575↗2023-07-15 ▶ OracleOracle Oracle Commerce Risk Matrix: Platform (OWASP Java HTML Sanitizer ) — CVE-2021-42575↗2023-04-15 ▶