CVE-2024-49412: Input Validation
Published Dec 3, 2024
·Updated
Improper input validation in Settings prior to SMR Dec-2024 Release 1 allows local attackers to broadcast signal for discovering Bluetooth on Galaxy Watch.
Affected Software
1 affected component
Samsung Galaxy Watch<SMR Dec-2024 Release 1
Event History
Dec 3, 2024
CVE Published
via MITRE·05:47 AM
Data Sourced
via MITRE·05:47 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-49412?
CVE-2024-49412 is categorized as a medium severity vulnerability due to the potential for local attackers to exploit improper input validation.
2
How do I fix CVE-2024-49412?
To fix CVE-2024-49412, users should update their Galaxy Watch to the SMR Dec-2024 Release 1 or later.
3
What type of attack can be performed using CVE-2024-49412?
CVE-2024-49412 allows local attackers to broadcast a signal for discovering Bluetooth services on affected Galaxy Watch devices.
4
Which devices are affected by CVE-2024-49412?
CVE-2024-49412 affects Samsung Galaxy Watch devices prior to the SMR Dec-2024 Release 1.
5
Is remote exploitation possible with CVE-2024-49412?
No, CVE-2024-49412 requires local access to the affected device for exploitation.