CVE-2022-23434

A vulnerability using PendingIntent in Bixby Vision prior to versions 3.7.60.8 in Android S(12), 3.7.50.6 in Andorid R(11) and below allows attackers to execute privileged action by hijacking and modifying the intent.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:samsung:bixby:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:samsung:bixby:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*

History

21 Nov 2024, 06:48

Type Values Removed Values Added
CVSS v2 : 2.1
v3 : 3.3
v2 : 2.1
v3 : 4.4
References () https://security.samsungmobile.com/serviceWeb.smsb?year=2022&month=2 - Vendor Advisory () https://security.samsungmobile.com/serviceWeb.smsb?year=2022&month=2 - Vendor Advisory

Information

Published : 2022-02-11 18:15

Updated : 2024-11-21 06:48


NVD link : CVE-2022-23434

Mitre link : CVE-2022-23434

CVE.ORG link : CVE-2022-23434


JSON object : View

Products Affected

samsung

  • bixby

google

  • android
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

NVD-CWE-noinfo