CVE-2022-28777: Medium severity samsung members vulnerability
Published Apr 11, 2022
·Updated
Improper access control vulnerability in Samsung Members prior to version 13.6.08.5 allows local attacker to execute call function without CALLPHONE permission.
Affected Software
1 affected component
Samsung Members<13.6.08.5
Event History
Apr 11, 2022
CVE Published
via MITRE·07:37 PM
Data Sourced
via MITRE·07:37 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-28777?
CVE-2022-28777 is classified as a high severity vulnerability due to improper access control allowing unauthorized call function execution.
2
How do I fix CVE-2022-28777?
To fix CVE-2022-28777, upgrade Samsung Members to version 13.6.08.5 or later.
3
Who is affected by CVE-2022-28777?
Users of Samsung Members prior to version 13.6.08.5 are affected by CVE-2022-28777.
4
What kind of attacks can CVE-2022-28777 enable?
CVE-2022-28777 allows local attackers to make phone calls without the necessary CALL_PHONE permission.
5
Is there any workaround for CVE-2022-28777?
The best workaround for CVE-2022-28777 is to update the Samsung Members app to the latest version.