cbcvebase.

Samsung Mobile Smartthings vulnerabilities

11 known vulnerabilities affecting samsung_mobile/smartthings.

Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH8MEDIUM1LOW1

Vulnerabilities

Page 1 of 1
CVE-2021-25508P3CRITICALCVSS 9.8≥ -, < 1.7.73.222021-11-05
CVE-2021-25508 [CRITICAL] CWE-269 CVE-2021-25508: Improper privilege management vulnerability in API Key used in SmartThings prior to 1.7.73.22 allows Improper privilege management vulnerability in API Key used in SmartThings prior to 1.7.73.22 allows an attacker to abuse the API key without limitation.
nvd
CVE-2022-39866P3HIGHCVSS 7.5≥ unspecified, < 1.7.89.02022-10-07
CVE-2022-39866 [HIGH] CWE-284 CVE-2022-39866: Improper access control vulnerability in RegisteredEventMediator.kt SmartThings prior to version 1.7 Improper access control vulnerability in RegisteredEventMediator.kt SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast.
nvd
CVE-2022-39869P3HIGHCVSS 7.5≥ unspecified, < 1.7.89.02022-10-07
CVE-2022-39869 [HIGH] CWE-284 CVE-2022-39869: Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via REMOVE_PERSISTENT_BANNER broadcast.
nvd
CVE-2022-39865P3HIGHCVSS 7.5≥ unspecified, < 1.7.89.02022-10-07
CVE-2022-39865 [HIGH] CWE-284 CVE-2022-39865: Improper access control vulnerability in ContentsSharingActivity.java SmartThings prior to version 1 Improper access control vulnerability in ContentsSharingActivity.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast.
nvd
CVE-2022-39867P3HIGHCVSS 7.5≥ unspecified, < 1.7.89.02022-10-07
CVE-2022-39867 [HIGH] CWE-284 CVE-2022-39867: Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via SHOW_PERSISTENT_BANNER broadcast.
nvd
CVE-2022-39870P3HIGHCVSS 7.5≥ unspecified, < 1.7.89.02022-10-07
CVE-2022-39870 [HIGH] CWE-284 CVE-2022-39870: Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via PUSH_MESSAGE_RECEIVED broadcast.
nvd
CVE-2022-39871P3HIGHCVSS 7.5≥ unspecified, < 1.7.89.02022-10-07
CVE-2022-39871 [HIGH] CWE-284 CVE-2022-39871: Improper access control vulnerability cloudNotificationManager.java in SmartThings prior to version Improper access control vulnerability cloudNotificationManager.java in SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcasts.
nvd
CVE-2022-39868P3HIGHCVSS 7.5≥ unspecified, < 1.7.89.02022-10-07
CVE-2022-39868 [HIGH] CWE-284 CVE-2022-39868: Improper access control vulnerability in GedSamsungAccount.kt SmartThings prior to version 1.7.89.0 Improper access control vulnerability in GedSamsungAccount.kt SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast.
nvd
CVE-2022-39864P3HIGHCVSS 7.5≥ unspecified, < 1.7.89.252022-10-07
CVE-2022-39864 [HIGH] CWE-284 CVE-2022-39864: Improper access control vulnerability in WifiSetupLaunchHelper in SmartThings prior to version 1.7.8 Improper access control vulnerability in WifiSetupLaunchHelper in SmartThings prior to version 1.7.89.25 allows attackers to access sensitive information via implicit intent.
nvd
CVE-2021-25378P4MEDIUMCVSS 5.3≥ unspecified, < 1.7.63.62021-04-09
CVE-2021-25378 [MEDIUM] CWE-20 CVE-2021-25378: Improper access control of certain port in SmartThings prior to version 1.7.63.6 allows remote tempo Improper access control of certain port in SmartThings prior to version 1.7.63.6 allows remote temporary denial of service.
nvd
CVE-2021-25404P4LOWCVSS 3.3≥ unspecified, < 1.7.64.212021-06-11
CVE-2021-25404 [LOW] CWE-922 CVE-2021-25404: Information Exposure vulnerability in SmartThings prior to version 1.7.64.21 allows attacker to acce Information Exposure vulnerability in SmartThings prior to version 1.7.64.21 allows attacker to access user information via log.
nvd
Samsung Mobile Smartthings vulnerabilities | cvebase