First published: Fri Sep 09 2022(Updated: )
Improper Handling of Insufficient Permissions or Privileges vulnerability in Waterplugin prior to 2.2.11.22040751 allows attacker to access device IMEI and Serial number.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Galaxy Watch Plugin | <2.2.11.22040751 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36874 is classified as a high severity vulnerability due to unauthorized access to sensitive device information.
To resolve CVE-2022-36874, update the Waterplugin to version 2.2.11.22040751 or later.
CVE-2022-36874 affects Samsung Galaxy Watch Plugin versions prior to 2.2.11.22040751.
An attacker exploiting CVE-2022-36874 can gain access to sensitive information such as the device IMEI and Serial number.
CVE-2022-36874 is primarily a local attack vulnerability, requiring the attacker to have access to the affected device.