PT-2023-12258 · Samsung · Samsung Syncthru Web Service
Published
2023-08-22
·
Updated
2024-10-03
·
CVE-2021-35309
CVSS v3.1
7.5
High
| Vector | AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Samsung SyncThru Web Service version 5.93 06-09-2014
Description
The issue allows attackers to gain escalated privileges via Man-In-The-Middle (MITM) attacks. MITM attacks involve intercepting communication between two parties to steal sensitive information or gain unauthorized access.
Recommendations
For Samsung SyncThru Web Service version 5.93 06-09-2014, consider implementing additional security measures to prevent MITM attacks, such as encrypting communication channels and verifying the authenticity of devices connecting to the service. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Samsung Syncthru Web Service