PT-2023-12258 · Samsung · Samsung Syncthru Web Service

Published

2023-08-22

·

Updated

2024-10-03

·

CVE-2021-35309

CVSS v3.1

7.5

High

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Samsung SyncThru Web Service version 5.93 06-09-2014
Description The issue allows attackers to gain escalated privileges via Man-In-The-Middle (MITM) attacks. MITM attacks involve intercepting communication between two parties to steal sensitive information or gain unauthorized access.
Recommendations For Samsung SyncThru Web Service version 5.93 06-09-2014, consider implementing additional security measures to prevent MITM attacks, such as encrypting communication channels and verifying the authenticity of devices connecting to the service. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2021-35309

Affected Products

Samsung Syncthru Web Service