Improper Authentication in Samsung Mobile Firmware - CVE-2024-20803

 

Improper Authentication in Samsung Mobile Firmware - CVE-2024-20803

Published: January 8, 2024


Vulnerability identifier: #VU85081
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-20803
CWE-ID: CWE-287
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to bypass authentication process.

The vulnerability exists due to an error in Bluetooth pairing process. An attacker with physical proximity to device can establish pairing process without user interaction.


Affected software

Samsung Mobile Firmware

How to mitigate CVE-2024-20803

Install updates from vendor's website.

Samsung Mobile Firmware - update to SMR-JAN-2024

External References

Related Security Bulletins