Multiple vulnerabilities in Samsung Account



Published: 2022-10-13
Risk Medium
Patch available YES
Number of vulnerabilities 3
CVE-ID CVE-2022-39874
CVE-2022-39875
CVE-2022-39863
CWE-ID CWE-532
CWE-284
CWE-601
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
Account
Mobile applications / Apps for mobile phones

Vendor

Security Bulletin

This security bulletin contains information about 3 vulnerabilities.

1) Inclusion of Sensitive Information in Log Files

EUVDB-ID: #VU68292

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2022-39874

CWE-ID: CWE-532 - Information Exposure Through Log Files

Exploit availability: No

Description

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to software stores sensitive information into log files. A local user can read the log files and gain access to sensitive data, leading to unauthorized logout.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Account: before 13.5.01.3


CPE2.3
External links

http://security.samsungmobile.com/serviceWeb.smsb?year=2022&month=10

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

2) Improper access control

EUVDB-ID: #VU68293

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2022-39875

CWE-ID: CWE-284 - Improper Access Control

Exploit availability: No

Description

The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper component protection. A local user can bypass implemented security restrictions and force unauthorized logout.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Account: before 13.5.01.3


CPE2.3
External links

http://security.samsungmobile.com/serviceWeb.smsb?year=2022&month=10

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

3) Open redirect

EUVDB-ID: #VU68294

Risk: Medium

CVSSv3.1:

CVE-ID: CVE-2022-39863

CWE-ID: CWE-601 - URL Redirection to Untrusted Site ('Open Redirect')

Exploit availability: No

Description

The vulnerability allows a remote attacker to redirect victims to arbitrary URL.

The vulnerability exists due to improper sanitization of user-supplied data. A remote attacker can create a link that leads to a trusted website, however, when clicked, redirects the victim to arbitrary domain.

Successful exploitation of this vulnerability may allow a remote attacker to perform a phishing attack and steal potentially sensitive information.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Account: before 13.5.01.3


CPE2.3
External links

http://security.samsungmobile.com/serviceWeb.smsb?year=2022&month=10

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?



###SIDEBAR###