Samsung Mobile Smart Things vulnerabilities

6 known vulnerabilities affecting samsung_mobile/smart_things.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2023-21432HIGHCVSS 7.8≥ unspecified, < 1.7.932023-02-09
CVE-2023-21432 [MEDIUM] CWE-285 CVE-2023-21432: Improper access control vulnerabilities in Smart Things prior to 1.7.93 allows to attacker to invite Improper access control vulnerabilities in Smart Things prior to 1.7.93 allows to attacker to invite others without authorization of the owner.
cvelistv5nvd
CVE-2022-30746HIGHCVSS 7.5≥ unspecified, < 1.7.85.122022-06-07
CVE-2022-30746 [HIGH] CWE-285 CVE-2022-30746: Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive i Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely using javascript interface API.
cvelistv5nvd
CVE-2022-30749HIGHCVSS 7.8≥ unspecified, < 1.7.85.252022-06-07
CVE-2022-30749 [LOW] CWE-287 CVE-2022-30749: Improper access control vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to a Improper access control vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to add arbitrary smart devices by bypassing login activity.
cvelistv5nvd
CVE-2022-30747MEDIUMCVSS 5.5≥ unspecified, < 1.7.85.252022-06-07
CVE-2022-30747 [MEDIUM] CWE-276 CVE-2022-30747: PendingIntent hijacking vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to a PendingIntent hijacking vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to access files without permission via implicit Intent.
cvelistv5nvd
CVE-2021-25447MEDIUMCVSS 5.3≥ -, < 1.7.67.252021-08-05
CVE-2021-25447 [MEDIUM] CWE-284 CVE-2021-25447: Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted app Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause local file inclusion in webview.
cvelistv5nvd
CVE-2021-25446MEDIUMCVSS 5.3≥ -, < 1.7.67.252021-08-05
CVE-2021-25446 [MEDIUM] CWE-284 CVE-2021-25446: Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted app Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause arbitrary webpage loading in webview.
cvelistv5nvd