PT-2022-20285 · Unknown · Smartthings

Sergey Toshin

·

Published

2022-06-07

·

Updated

2023-06-29

·

CVE-2022-30746

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Smart Things versions prior to 1.7.85.12
Description The issue is related to a missing caller check in Smart Things, allowing an attacker to access sensitive information remotely using the javascript interface API.
Recommendations For versions prior to 1.7.85.12, update to version 1.7.85.12 or later to resolve the issue.

Fix

Improper Authorization

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-30746

Affected Products

Smartthings