First published: Fri Oct 07 2022(Updated: )
Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via REMOVE_PERSISTENT_BANNER broadcast.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
SmartThings | <1.7.89.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-39869 is considered a high-severity vulnerability due to improper access control allowing sensitive information exposure.
To fix CVE-2022-39869, update the SmartThings app to version 1.7.89.0 or later.
CVE-2022-39869 allows attackers to access sensitive information through unauthorized broadcasts, compromising user data security.
CVE-2022-39869 affects all versions of SmartThings prior to version 1.7.89.0.
CVE-2022-39869 is classified as an improper access control vulnerability.