Описание
Improper authorization in PushMsgReceiver of Samsung Assistant prior to version 8.7.00.1 allows attacker to execute javascript interface. To trigger this vulnerability, user interaction is required.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 8.7.00.1 (исключая)
cpe:2.3:a:samsung:samsung_assistant:*:*:*:*:*:*:*:*
EPSS
Процентиль: 27%
0.00097
Низкий
4.4 Medium
CVSS3
5.4 Medium
CVSS3
Дефекты
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 4.4
github
больше 2 лет назад
Improper authorization in PushMsgReceiver of Samsung Assistant prior to version 8.7.00.1 allows attacker to execute javascript interface. To trigger this vulnerability, user interaction is required.
EPSS
Процентиль: 27%
0.00097
Низкий
4.4 Medium
CVSS3
5.4 Medium
CVSS3
Дефекты
NVD-CWE-noinfo