VDB

CISA-2023-30727

CISA-2023-30727 PUBLISHED CVSS 6.7 MEDIUM

Reported by Samsung Mobile · Published October 4, 2023

Improper access control vulnerability in SecSettings prior to SMR Oct-2023 Release 1 allows attackers to enable Wi-Fi and connect arbitrary Wi-Fi without User Interaction.

Risk Scores

CVSS 3.1
6.7
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Samsung MobileSamsung Mobile DevicesSMR Oct-2023 Release in Android 11, 12, 13
Samsung MobileSamsung Mobile DevicesSMR Oct-2023 Release in Android 11, 12, 13, SMR Oct-2023 Release in Android 11, 12, 13

Timeline

  • Oct 4, 2023 CVE Published
  • Sep 19, 2024 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›