CVE-2023-21437

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
09/02/2023
Last modified:
21/02/2023

Description

Improper access control vulnerability in Phone application prior to SMR Feb-2023 Release 1 allows local attackers to access sensitive information via implicit broadcast.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:samsung:android:10.0:-:*:*:*:*:*:*
cpe:2.3:o:samsung:android:10.0:smr-apr-2020-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:10.0:smr-apr-2021-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:10.0:smr-apr-2022-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:10.0:smr-apr-2023-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:10.0:smr-aug-2020-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:10.0:smr-aug-2021-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:10.0:smr-aug-2022-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:10.0:smr-aug-2023-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:10.0:smr-dec-2019-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:10.0:smr-dec-2020-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:10.0:smr-dec-2021-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:10.0:smr-dec-2022-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:10.0:smr-dec-2023-r1:*:*:*:*:*:*
cpe:2.3:o:samsung:android:10.0:smr-feb-2020-r1:*:*:*:*:*:*