PT-2022-23681 · Samsung · Samsung Members

Martin Heyden

·

Published

2022-09-09

·

Updated

2022-09-21

·

CVE-2022-36877

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Samsung Members versions prior to 4.3.00.11 Samsung Members version prior to 14.0.02.4 in China
Description The issue allows local attackers to access device identification via log, due to exposure of sensitive information in FaqSymptomCardViewModel.
Recommendations For versions prior to 4.3.00.11, update to version 4.3.00.11 or later. For version prior to 14.0.02.4 in China, update to version 14.0.02.4 or later.

Fix

Information Disclosure

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2022-36877

Affected Products

Samsung Members