CVE-2022-39893: Low severity samsung galaxy buds pro manager vulnerability
Published Nov 9, 2022
·Updated
Sensitive information exposure vulnerability in FmmBaseModel in Galaxy Buds Pro Manage prior to version 4.1.22092751 allows local attackers with log access permission to get device identifier data through device log.
Affected Software
1 affected component
Samsung Galaxy Buds Pro Manage<4.1.22092751
Event History
Nov 9, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-39893?
CVE-2022-39893 is rated as a medium severity vulnerability.
2
How do I fix CVE-2022-39893?
To fix CVE-2022-39893, update the Galaxy Buds Pro Manage app to version 4.1.22092751 or later.
3
What type of data is exposed in CVE-2022-39893?
CVE-2022-39893 exposes device identifier data to local attackers with log access permissions.
4
Who is affected by CVE-2022-39893?
Users of Samsung Galaxy Buds Pro Manage prior to version 4.1.22092751 are affected by CVE-2022-39893.
5
Is remote exploitation possible with CVE-2022-39893?
No, CVE-2022-39893 requires local access to exploit the sensitive information exposure.