PT-2022-21851 · Samsung · Charm

Sergey Toshin

·

Published

2022-08-05

·

Updated

2023-07-21

·

CVE-2022-33734

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Charm by Samsung versions prior to 1.2.3
Description The issue allows an attacker to obtain Bluetooth connection information without permission due to sensitive information exposure in the onCharacteristicChanged function.
Recommendations For versions prior to 1.2.3, update to version 1.2.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the onCharacteristicChanged function until a patch is available.

Fix

Weakness Enumeration

Related Identifiers

CVE-2022-33734

Affected Products

Charm