PT-2022-23680 · Samsung · Samsung Pass

Published

2022-09-09

·

Updated

2023-06-27

·

CVE-2022-36876

CVSS v3.1

2.4

Low

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Samsung Pass versions prior to 4.0.04.10
Description The issue is related to improper authorization in UPI payment, allowing physical attackers to access the account list without authentication.
Recommendations For versions prior to 4.0.04.10, update to version 4.0.04.10 or later to resolve the issue.

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-36876

Affected Products

Samsung Pass