CVE-2022-36876: Low severity samsung pass vulnerability
Published Sep 9, 2022
·Updated
Improper authorization in UPI payment in Samsung Pass prior to version 4.0.04.10 allows physical attackers to access account list without authentication.
Affected Software
1 affected component
Samsung Samsung Pass Android<4.0.04.10
Event History
Sep 9, 2022
CVE Published
via MITRE·02:39 PM
Data Sourced
via MITRE·02:39 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-36876?
CVE-2022-36876 has a high severity due to improper authorization that can allow unauthorized access to sensitive account information.
2
How do I fix CVE-2022-36876?
To mitigate CVE-2022-36876, update Samsung Pass to version 4.0.04.10 or later.
3
Who is affected by CVE-2022-36876?
Users of Samsung Pass prior to version 4.0.04.10 on Android devices are affected by CVE-2022-36876.
4
What type of attack does CVE-2022-36876 enable?
CVE-2022-36876 allows physical attackers to access the account list of the Samsung Pass application without proper authentication.
5
Is remote exploitation possible with CVE-2022-36876?
No, CVE-2022-36876 requires physical access to the device for exploitation.