Samsung Pass vulnerabilities

5 known vulnerabilities affecting samsung/samsung_pass.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM3LOW1

Vulnerabilities

Page 1 of 1
CVE-2022-36851MEDIUMCVSS 4.6fixed in 4.0.03.12022-09-09
CVE-2022-36851 [LOW] CWE-284 CVE-2022-36851: Improper access control vulnerability in Samsung pass prior to version 4.0.03.1 allow physical attac Improper access control vulnerability in Samsung pass prior to version 4.0.03.1 allow physical attackers to access data of Samsung pass on a certain state of an unlocked device.
nvd
CVE-2022-36876LOWCVSS 2.4fixed in 4.0.04.102022-09-09
CVE-2022-36876 [LOW] CWE-285 CVE-2022-36876: Improper authorization in UPI payment in Samsung Pass prior to version 4.0.04.10 allows physical att Improper authorization in UPI payment in Samsung Pass prior to version 4.0.04.10 allows physical attackers to access account list without authentication.
nvd
CVE-2022-30730MEDIUMCVSS 4.6fixed in 1.0.00.332022-06-07
CVE-2022-30730 [MEDIUM] CWE-285 CVE-2022-30730: Improper authorization in Samsung Pass prior to 1.0.00.33 allows physical attackers to acess account Improper authorization in Samsung Pass prior to 1.0.00.33 allows physical attackers to acess account list without authentication.
nvd
CVE-2022-27841MEDIUMCVSS 4.3fixed in 3.7.07.52022-04-11
CVE-2022-27841 [MEDIUM] CWE-703 CVE-2022-27841: Improper exception handling in Samsung Pass prior to version 3.7.07.5 allows physical attacker to vi Improper exception handling in Samsung Pass prior to version 3.7.07.5 allows physical attacker to view the screen that is previously running without authentication
nvd
CVE-2021-25505HIGHCVSS 7.8fixed in 3.0.02.42021-11-05
CVE-2021-25505 [LOW] CWE-287 CVE-2021-25505: Improper authentication in Samsung Pass prior to 3.0.02.4 allows to use app without authentication w Improper authentication in Samsung Pass prior to 3.0.02.4 allows to use app without authentication when lockscreen is unlocked.
nvd