Improper input validation in Samsung Health prior to version 6.27.0.113 allows local attackers to write arbitrary document files to the sandbox of Samsung Health. User interaction is required for triggering this vulnerability.
References
Link | Resource |
---|---|
https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=07 | Vendor Advisory |
https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=07 | Vendor Advisory |
Configurations
History
21 Nov 2024, 09:19
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.4 |
References | () https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=07 - Vendor Advisory |
02 Jul 2024, 18:04
Type | Values Removed | Values Added |
---|---|---|
First Time |
Samsung
Samsung health |
|
References | () https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=07 - Vendor Advisory | |
CWE | NVD-CWE-noinfo | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 3.3 |
CPE | cpe:2.3:a:samsung:health:*:*:*:*:*:*:*:* |
02 Jul 2024, 12:09
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
02 Jul 2024, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-02 10:15
Updated : 2024-11-21 09:19
NVD link : CVE-2024-34597
Mitre link : CVE-2024-34597
CVE.ORG link : CVE-2024-34597
JSON object : View
Products Affected
samsung
- health
CWE