CVE-2023-30677: Medium severity samsung pass vulnerability
Published Jul 6, 2023
·Updated
Improper access control vulnerability in Samsung Pass prior to version 4.2.03.1 allows physical attackers to access data of Samsung Pass on a certain state of an unlocked device.
Affected Software
1 affected component
Samsung Pass<4.2.03.1
Event History
Jul 6, 2023
CVE Published
via MITRE·02:51 AM
Data Sourced
via MITRE·02:51 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability in Samsung Pass?
The vulnerability is an improper access control vulnerability in Samsung Pass.
2
What is the severity of CVE-2023-30677?
The severity of CVE-2023-30677 is medium with a severity value of 4.6.
3
How can physical attackers exploit the vulnerability?
Physical attackers can exploit the vulnerability to access data of Samsung Pass on a certain state of an unlocked device.
4
Which version of Samsung Pass is affected by the vulnerability?
Samsung Pass prior to version 4.2.03.1 is affected by the vulnerability.
5
Is there a fix available for CVE-2023-30677?
Yes, updating to Samsung Pass version 4.2.03.1 or higher will fix the vulnerability.