Samsung Cloud vulnerabilities
8 known vulnerabilities affecting samsung/cloud.
Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM2LOW3
Vulnerabilities
Page 1 of 1
CVE-2026-20975LOWCVSS 2.1fixed in 5.6.112026-01-09
CVE-2026-20975 [LOW] CVE-2026-20975: Improper handling of insufficient permission in Samsung Cloud prior to version 5.6.11 allows local a
Improper handling of insufficient permission in Samsung Cloud prior to version 5.6.11 allows local attackers to access specific files in arbitrary path.
nvd
CVE-2024-20851MEDIUMCVSS 5.5fixed in 5.3.00.42024-04-02
CVE-2024-20851 [MEDIUM] CVE-2024-20851: Improper access control vulnerability in Samsung Data Store prior to version 5.3.00.4 allows local a
Improper access control vulnerability in Samsung Data Store prior to version 5.3.00.4 allows local attackers to launch arbitrary activity with Samsung Data Store privilege.
nvd
CVE-2023-42578HIGHCVSS 7.5≤ 5.2.00.72023-12-05
CVE-2023-42578 [MEDIUM] CWE-755 CVE-2023-42578: Improper handling of insufficient permissions or privileges vulnerability in Samsung Data Store prio
Improper handling of insufficient permissions or privileges vulnerability in Samsung Data Store prior to version 5.2.00.7 allows remote attackers to access location information without permission.
nvd
CVE-2023-21447LOWCVSS 3.3fixed in 5.3.0.322023-02-09
CVE-2023-21447 [MEDIUM] CWE-284 CVE-2023-21447: Improper access control vulnerabilities in Samsung Cloud prior to version 5.3.0.32 allows local atta
Improper access control vulnerabilities in Samsung Cloud prior to version 5.3.0.32 allows local attackers to access information with Samsung Cloud's privilege via implicit intent.
nvd
CVE-2023-21448LOWCVSS 3.3fixed in 5.3.0.322023-02-09
CVE-2023-21448 [MEDIUM] CWE-22 CVE-2023-21448: Path traversal vulnerability in Samsung Cloud prior to version 5.3.0.32 allows attacker to access sp
Path traversal vulnerability in Samsung Cloud prior to version 5.3.0.32 allows attacker to access specific png file.
nvd
CVE-2022-33713HIGHCVSS 7.5fixed in 5.2.02022-07-12
CVE-2022-33713 [HIGH] CWE-285 CVE-2022-33713: Implicit Intent hijacking vulnerability in Samsung Cloud prior to version 5.2.0 allows attacker to g
Implicit Intent hijacking vulnerability in Samsung Cloud prior to version 5.2.0 allows attacker to get sensitive information.
nvd
CVE-2022-24932MEDIUMCVSS 4.6fixed in 5.1.0.82022-03-10
CVE-2022-24932 [MEDIUM] CWE-424 CVE-2022-24932: Improper Protection of Alternate Path vulnerability in Setup wizard process prior to SMR Mar-2022 Re
Improper Protection of Alternate Path vulnerability in Setup wizard process prior to SMR Mar-2022 Release 1 allows physical attacker package installation before finishing Setup wizard.
nvd
CVE-2021-25368HIGHCVSS 7.5fixed in 4.7.0.32021-03-25
CVE-2021-25368 [LOW] CWE-287 CVE-2021-25368: Hijacking vulnerability in Samsung Cloud prior to version 4.7.0.3 allows attackers to intercept when
Hijacking vulnerability in Samsung Cloud prior to version 4.7.0.3 allows attackers to intercept when the provider is executed.
nvd