Samsung Smart Switch vulnerabilities
13 known vulnerabilities affecting samsung/smart_switch.
Total CVEs
13
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM8
Vulnerabilities
Page 1 of 1
CVE-2026-20996HIGHCVSS 7.1fixed in 3.7.69.152026-03-16
CVE-2026-20996 [HIGH] CWE-327 CVE-2026-20996: Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.69.15 allows r
Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.69.15 allows remote attackers to configure a downgraded scheme for authentication.
nvd
CVE-2026-20999HIGHCVSS 7.1fixed in 3.7.69.152026-03-16
CVE-2026-20999 [HIGH] CWE-294 CVE-2026-20999: Authentication bypass by replay in Smart Switch prior to version 3.7.69.15 allows remote attackers t
Authentication bypass by replay in Smart Switch prior to version 3.7.69.15 allows remote attackers to trigger privileged functions.
nvd
CVE-2026-20998HIGHCVSS 7.1fixed in 3.7.69.152026-03-16
CVE-2026-20998 [HIGH] CVE-2026-20998: Improper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass
Improper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authentication.
nvd
CVE-2026-21005HIGHCVSS 7.1fixed in 3.7.69.152026-03-16
CVE-2026-21005 [HIGH] CWE-22 CVE-2026-21005: Path traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arb
Path traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Smart Switch privilege.
nvd
CVE-2026-20997MEDIUMCVSS 5.3fixed in 3.7.69.152026-03-16
CVE-2026-20997 [MEDIUM] CWE-347 CVE-2026-20997: Improper verification of cryptographic signature in Smart Switch prior to version 3.7.69.15 allows r
Improper verification of cryptographic signature in Smart Switch prior to version 3.7.69.15 allows remote attackers to potentially bypass authentication.
nvd
CVE-2026-20995MEDIUMCVSS 5.3fixed in 3.7.69.152026-03-16
CVE-2026-20995 [MEDIUM] CWE-306 CVE-2026-20995: Exposure of sensitive functionality to an unauthorized actor in Smart Switch prior to version 3.7.69
Exposure of sensitive functionality to an unauthorized actor in Smart Switch prior to version 3.7.69.15 allows remote attackers to set a specific configuration.
nvd
CVE-2026-21004MEDIUMCVSS 6.9fixed in 3.7.69.152026-03-16
CVE-2026-21004 [MEDIUM] CWE-287 CVE-2026-21004: Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trig
Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of service.
nvd
CVE-2025-21078MEDIUMCVSS 6.5fixed in 3.7.68.62025-11-05
CVE-2025-21078 [HIGH] CVE-2025-21078: Use of insufficiently random value of secretKey in Smart Switch prior to version 3.7.68.6 allows adj
Use of insufficiently random value of secretKey in Smart Switch prior to version 3.7.68.6 allows adjacent attackers to access backup data from applications.
nvd
CVE-2025-21062HIGHCVSS 7.8fixed in 3.7.67.22025-10-10
CVE-2025-21062 [HIGH] CWE-327 CVE-2025-21062: Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.67.2 allows lo
Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.67.2 allows local attackers to replace the restoring application. User interaction is required for triggering this vulnerability.
nvd
CVE-2025-21064MEDIUMCVSS 6.5fixed in 3.7.67.22025-10-10
CVE-2025-21064 [HIGH] CVE-2025-21064: Improper authentication in Smart Switch prior to version 3.7.66.6 allows adjacent attackers to acces
Improper authentication in Smart Switch prior to version 3.7.66.6 allows adjacent attackers to access transferring data.
nvd
CVE-2025-21061MEDIUMCVSS 5.5fixed in 3.7.67.22025-10-10
CVE-2025-21061 [HIGH] CWE-312 CVE-2025-21061: Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local at
Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access sensitive data. User interaction is required for triggering this vulnerability.
nvd
CVE-2025-21060MEDIUMCVSS 5.5fixed in 3.7.67.22025-10-10
CVE-2025-21060 [MEDIUM] CWE-312 CVE-2025-21060: Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local at
Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access backup data from applications. User interaction is required for triggering this vulnerability.
nvd
CVE-2025-20996MEDIUMCVSS 5.0fixed in 3.7.64.102025-06-04
CVE-2025-20996 [MEDIUM] CVE-2025-20996: Improper authorization in Smart Switch installed on non-Samsung Device prior to version 3.7.64.10 al
Improper authorization in Smart Switch installed on non-Samsung Device prior to version 3.7.64.10 allows local attackers to read data with the privilege of Smart Switch. User interaction is required for triggering this vulnerability.
nvd