First published: Tue Nov 07 2023(Updated: )
Implicit intent hijacking vulnerability in Firewall application prior to versions 12.1.00.24 in Android 11, 13.1.00.16 in Android 12 and 14.1.00.7 in Android 13 allows 3rd party application to tamper the database of Firewall.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Firewall | <12.1.00.24 | |
Samsung Android | =11.0 | |
Samsung Firewall | <13.1.00.16 | |
Samsung Android | =12.0 | |
Samsung Firewall | <14.1.00.7 | |
Samsung Android | =13.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-42552 is an implicit intent hijacking vulnerability in the Firewall application prior to versions 12.1.00.24 in Android 11, 13.1.00.16 in Android 12, and 14.1.00.7 in Android 13, which allows a 3rd party application to tamper with the Firewall database.
CVE-2023-42552 affects Samsung Firewall versions up to 12.1.00.24 in Android 11, up to 13.1.00.16 in Android 12, and up to 14.1.00.7 in Android 13.
The severity of CVE-2023-42552 is medium with a CVSS score of 4.4.
To fix CVE-2023-42552, update your Samsung Firewall application to version 12.1.00.24 if you are using Android 11, version 13.1.00.16 if you are using Android 12, or version 14.1.00.7 if you are using Android 13.
You can find more information about CVE-2023-42552 on the Samsung Mobile Security website: [https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=11]