CVE-2023-42550: Medium severity samsung account sdk vulnerability
Published Nov 7, 2023
·Updated
Use of implicit intent for sensitive communication vulnerability in startSignIn in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.
Affected Software
1 affected component
samsung Account<14.5.00.7
Event History
Nov 7, 2023
CVE Published
via MITRE·07:49 AM
Data Sourced
via MITRE·07:49 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-42550?
CVE-2023-42550 is a vulnerability that allows attackers to access arbitrary files with Samsung Account privilege.
2
What is the severity of CVE-2023-42550?
The severity of CVE-2023-42550 is medium with a CVSS score of 6.5.
3
How does CVE-2023-42550 impact Samsung Account?
CVE-2023-42550 allows attackers to access arbitrary files by exploiting the use of implicit intent for sensitive communication in the startSignIn function of Samsung Account prior to version 14.5.00.7.
4
Is there a fix for CVE-2023-42550?
There is no known fix available for CVE-2023-42550 at the moment.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-42550?
The CWE ID for CVE-2023-42550 is 927.