CVE-2024-20850: Medium severity samsung pay vulnerability
Published Apr 2, 2024
·Updated
Use of Implicit Intent for Sensitive Communication in Samsung Pay prior to version 5.4.99 allows local attackers to access information of Samsung Pay.
Affected Software
2 affected components
Samsung Samsung Pay<5.4.99
Samsung Samsung Pay<5.4.99
Event History
Apr 2, 2024
CVE Published
via MITRE·02:59 AM
Data Sourced
via MITRE·02:59 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-20850?
CVE-2024-20850 is classified as a high severity vulnerability due to its potential to expose sensitive information in Samsung Pay.
2
How do I fix CVE-2024-20850?
To mitigate CVE-2024-20850, update Samsung Pay to version 5.4.99 or later.
3
Who is affected by CVE-2024-20850?
CVE-2024-20850 affects users of Samsung Pay prior to version 5.4.99.
4
What type of vulnerability is CVE-2024-20850?
CVE-2024-20850 is an implicit intent vulnerability that allows local attackers to access sensitive communication information.
5
Can CVE-2024-20850 be exploited remotely?
No, CVE-2024-20850 can only be exploited by local attackers with access to the device.