PT-2023-18214 · Samsung · Samsung Cloud

Wang Kailong

+1

·

Published

2023-02-09

·

Updated

2023-02-17

·

CVE-2023-21447

CVSS v3.1

4.0

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Samsung Cloud versions prior to 5.3.0.32
Description The issue is related to improper access control in Samsung Cloud, allowing local attackers to access information with Samsung Cloud's privilege via implicit intent.
Recommendations For versions prior to 5.3.0.32, update to version 5.3.0.32 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information stored in Samsung Cloud until the update is applied.

Fix

Improper Access Control

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

CVE-2023-21447

Affected Products

Samsung Cloud