VDB
CVE-2022-39851
CVE-2022-39851
PUBLISHED
CVSS 4 MEDIUM
Improper access control vulnerability in CocktailBarService prior to SMR Oct-2022 Release 1 allows local attacker to bind service that require BIND_REMOTEVIEWS permission.
EPSS 0.11% · 1.3th percentile
Risk Scores
CVSS 3.1
4
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS Score
0.11%
1.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| android | 11.0, 12.0, 10.0 | |
| Samsung Mobile | Samsung Mobile Devices | Q(10), R(11), S(12) |
Timeline
- Oct 7, 2022 CVE Published
- Oct 8, 2022 EPSS Score
- Nov 21, 2022 EPSS Score
- Jan 4, 2023 EPSS Score
- Feb 18, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 17, 2023 EPSS Score
- Jun 30, 2023 EPSS Score
- Aug 13, 2023 EPSS Score
- Sep 26, 2023 EPSS Score
- Nov 10, 2023 EPSS Score