CVE-2023-21495: Medium severity samsung android vulnerability
Improper access control vulnerability in Knox Enrollment Service prior to SMR May-2023 Release 1 allow attacker install KSP app when device admin is set.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-21495?
CVE-2023-21495 is classified as a moderate severity vulnerability due to improper access control.
How do I fix CVE-2023-21495?
To fix CVE-2023-21495, it is recommended to update the affected Samsung devices to the latest software version released in May 2023 or later.
Which devices are affected by CVE-2023-21495?
CVE-2023-21495 affects Samsung devices running Android 11.0, including various security maintenance releases prior to May 2023.
What exploitation is possible with CVE-2023-21495?
An attacker exploiting CVE-2023-21495 could install the KSP app on the device, circumventing administrative controls.
Is there a workaround for CVE-2023-21495?
Currently, there is no official workaround for CVE-2023-21495; updating the device's firmware is the only recommended solution.