CVE-2023-42546: Medium severity samsung account sdk vulnerability
Published Nov 7, 2023
·Updated
Use of implicit intent for sensitive communication vulnerability in startAgreeToDisclaimerActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.
Affected Software
1 affected component
samsung Account<14.5.00.7
Event History
Nov 7, 2023
CVE Published
07:49 AM
Data Sourced
07:49 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-42546.
2
What is the severity of CVE-2023-42546?
The severity of CVE-2023-42546 is medium (6.5).
3
What is the affected software for CVE-2023-42546?
The affected software for CVE-2023-42546 is Samsung Account prior to version 14.5.00.7.
4
How can attackers exploit CVE-2023-42546?
Attackers can exploit CVE-2023-42546 by accessing arbitrary files with Samsung Account privilege using a use of implicit intent for sensitive communication in startAgreeToDisclaimerActivity.
5
Where can I find more information about CVE-2023-42546?
You can find more information about CVE-2023-42546 at this [link](https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=11).