CVE-2022-36878: Infoleak
Published Sep 9, 2022
·Updated
Exposure of Sensitive Information in Find My Mobile prior to version 7.2.25.14 allows local attacker to access IMEI via log.
Affected Software
1 affected component
Samsung Find My Mobile<7.2.25.14
Event History
Sep 9, 2022
CVE Published
via MITRE·02:39 PM
Data Sourced
via MITRE·02:39 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-36878?
CVE-2022-36878 is considered a medium severity vulnerability due to the exposure of sensitive information.
2
How do I fix CVE-2022-36878?
To fix CVE-2022-36878, upgrade to Samsung Find My Mobile version 7.2.25.14 or later.
3
What type of information is exposed in CVE-2022-36878?
CVE-2022-36878 allows a local attacker to access the device's IMEI number via log files.
4
Who is affected by CVE-2022-36878?
Users of Samsung Find My Mobile prior to version 7.2.25.14 are affected by CVE-2022-36878.
5
Can CVE-2022-36878 be exploited remotely?
CVE-2022-36878 cannot be exploited remotely; it requires local access to the device.