Samsung Health vulnerabilities
11 known vulnerabilities affecting samsung/health.
Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM7LOW2
Vulnerabilities
Page 1 of 1
CVE-2025-21059MEDIUMCVSS 5.5fixed in 6.30.5.1052025-10-10
CVE-2025-21059 [MEDIUM] CVE-2025-21059: Improper authorization in Samsung Health prior to version 6.30.5.105 allows local attackers to acces
Improper authorization in Samsung Health prior to version 6.30.5.105 allows local attackers to access data in Samsung Health.
nvd
CVE-2025-21019MEDIUMCVSS 5.5fixed in 6.30.1.0032025-08-06
CVE-2025-21019 [MEDIUM] CVE-2025-21019: Improper authorization in Samsung Health prior to version 6.30.1.003 allows local attackers to acces
Improper authorization in Samsung Health prior to version 6.30.1.003 allows local attackers to access data in Samsung Health. User interaction is required for triggering this vulnerability.
nvd
CVE-2024-34597LOWCVSS 3.3fixed in 6.27.0.1132024-07-02
CVE-2024-34597 [MEDIUM] CVE-2024-34597: Improper input validation in Samsung Health prior to version 6.27.0.113 allows local attackers to wr
Improper input validation in Samsung Health prior to version 6.27.0.113 allows local attackers to write arbitrary document files to the sandbox of Samsung Health. User interaction is required for triggering this vulnerability.
nvd
CVE-2023-42539MEDIUMCVSS 5.5fixed in 6.252023-11-07
CVE-2023-42539 [MEDIUM] CVE-2023-42539: PendingIntent hijacking vulnerability in ChallengeNotificationManager in Samsung Health prior to ver
PendingIntent hijacking vulnerability in ChallengeNotificationManager in Samsung Health prior to version 6.25 allows local attackers to access data.
nvd
CVE-2023-30737MEDIUMCVSS 5.5fixed in 6.24.3.0072023-10-04
CVE-2023-30737 [MEDIUM] CVE-2023-30737: Improper access control vulnerability in Samsung Health prior to version 6.24.3.007 allows attackers
Improper access control vulnerability in Samsung Health prior to version 6.24.3.007 allows attackers to access sensitive information via implicit intent.
nvd
CVE-2023-30734MEDIUMCVSS 5.5fixed in 6.24.3.0072023-10-04
CVE-2023-30734 [MEDIUM] CVE-2023-30734: Improper access control vulnerability in Samsung Health prior to version 6.24.3.007 allows attackers
Improper access control vulnerability in Samsung Health prior to version 6.24.3.007 allows attackers to access sensitive information via implicit intent.
nvd
CVE-2023-30723CRITICALCVSS 9.8fixed in 6.24.2.0112023-09-06
CVE-2023-30723 [MEDIUM] CVE-2023-30723: Improper input validation vulnerability in Samsung Health prior to version 6.24.2.011 allows attacke
Improper input validation vulnerability in Samsung Health prior to version 6.24.2.011 allows attackers to write arbitrary file with Samsung Health privilege.
nvd
CVE-2022-22283LOWCVSS 3.3fixed in 6.20.1.0052022-01-10
CVE-2022-22283 [LOW] CWE-287 CVE-2022-22283: Improper session management vulnerability in Samsung Health prior to 6.20.1.005 prevents logging out
Improper session management vulnerability in Samsung Health prior to 6.20.1.005 prevents logging out from Samsung Health App.
nvd
CVE-2021-25506MEDIUMCVSS 5.5fixed in 6.19.1.00012021-11-05
CVE-2021-25506 [MEDIUM] CWE-287 CVE-2021-25506: Non-existent provider in Samsung Health prior to 6.19.1.0001 allows attacker to access it via malici
Non-existent provider in Samsung Health prior to 6.19.1.0001 allows attacker to access it via malicious content provider or lead to denial of service.
nvd
CVE-2021-25401HIGHCVSS 7.8fixed in 6.162021-06-11
CVE-2021-25401 [HIGH] CWE-20 CVE-2021-25401: Intent redirection vulnerability in Samsung Health prior to version 6.16 allows attacker to execute
Intent redirection vulnerability in Samsung Health prior to version 6.16 allows attacker to execute privileged action.
nvd
CVE-2021-25425MEDIUMCVSS 5.3fixed in 6.172021-06-11
CVE-2021-25425 [MEDIUM] CWE-703 CVE-2021-25425: Improper check vulnerability in Samsung Health prior to version 6.17 allows attacker to read interna
Improper check vulnerability in Samsung Health prior to version 6.17 allows attacker to read internal cache data via exported component.
nvd