CVE-2022-30749

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
07/06/2022
Last modified:
16/06/2022

Description

Improper access control vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to add arbitrary smart devices by bypassing login activity.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:samsung:smartthings:*:*:*:*:*:android:*:* 1.7.85.25 (excluding)


References to Advisories, Solutions, and Tools