CVE-2023-21450: Low severity samsung one hand operation + vulnerability
Published Feb 9, 2023
·Updated
Missing Authorization vulnerability in One Hand Operation + prior to version 6.1.21 allows multi-users to access owner's widget without authorization via gesture setting.
Affected Software
1 affected component
Samsung One Hand Operation \+ Android<6.1.21
Event History
Feb 9, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-21450?
CVE-2023-21450 is classified as a missing authorization vulnerability that may allow unauthorized access to sensitive user settings.
2
How do I fix CVE-2023-21450?
To fix CVE-2023-21450, update the Samsung One Hand Operation + app to version 6.1.21 or later.
3
Who is affected by CVE-2023-21450?
CVE-2023-21450 affects users of Samsung One Hand Operation + versions prior to 6.1.21.
4
What type of vulnerability is CVE-2023-21450?
CVE-2023-21450 is a missing authorization vulnerability that allows multi-user access to restricted widgets.
5
What should I do if I cannot update for CVE-2023-21450?
If you cannot update, consider restricting access to the app or disabling its features until the update can be applied.