CVE-2022-23995: Medium severity samsung wear os vulnerability
Published Feb 11, 2022
·Updated
Unprotected component vulnerability in StBedtimeModeAlarmReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to change bedtime mode without a proper permission.
Affected Software
1 affected component
Samsung Wear Os<3.0
Event History
Feb 11, 2022
CVE Published
via MITRE·05:40 PM
Data Sourced
via MITRE·05:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-23995?
CVE-2022-23995 is an unprotected component vulnerability in StBedtimeModeAlarmReceiver in Wear OS 3.0 prior to the February 2022 firmware update.
2
What is the severity of CVE-2022-23995?
The severity of CVE-2022-23995 is rated as medium with a severity value of 3.3.
3
How can untrusted applications exploit CVE-2022-23995?
Untrusted applications can exploit CVE-2022-23995 to change bedtime mode without proper permission.
4
Which software versions of Samsung Wear OS are affected by CVE-2022-23995?
Samsung Wear OS versions up to and exclusive of 3.0 are affected by CVE-2022-23995.
5
How can I mitigate the vulnerability CVE-2022-23995?
To mitigate CVE-2022-23995, ensure you have installed the February 2022 firmware update for Wear OS 3.0 or later.