Insufficient Verification of Data Authenticity vulnerability in Routine prior to versions 2.6.30.6 in Android Q(10), 3.1.21.10 in Android R(11) and 3.5.2.23 in Android S(12) allows local attacker to access protected files via unused code.
References
Link | Resource |
---|---|
https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=02 | Vendor Advisory |
https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=02 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 07:42
Type | Values Removed | Values Added |
---|---|---|
References | () https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=02 - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.4 |
Information
Published : 2023-02-09 19:15
Updated : 2024-11-21 07:42
NVD link : CVE-2023-21441
Mitre link : CVE-2023-21441
CVE.ORG link : CVE-2023-21441
JSON object : View
Products Affected
samsung
- android
CWE
CWE-345
Insufficient Verification of Data Authenticity