SB2023120519 - Multiple vulnerabilities in Samsung Pass



SB2023120519 - Multiple vulnerabilities in Samsung Pass

Published: December 5, 2023

Security Bulletin ID SB2023120519
Severity
Low
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Physical access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Improper Authentication (CVE-ID: CVE-2023-42576)

The vulnerability allows an attacker to bypass authentication process.

The vulnerability exists due to an invalid exception handler. An attacker with physical access to device can bypass authentication process and gain unauthorized access to the device.


2) Improper Authentication (CVE-ID: CVE-2023-42575)

The vulnerability allows an attacker to bypass authentication process.

The vulnerability exists due to invalid flag setting. An attacker with physical access to device can bypass authentication process and gain unauthorized access to the application.


Remediation

Install update from vendor's website.