CVE-2024-49417: Low severity Smart Touch Smart Touch Call vulnerability
Published Dec 3, 2024
·Updated
Use of implicit intent for sensitive communication in Smart Touch Call prior to 1.0.0.8 allows local attackers to launch privileged activities. User interaction is required for triggering this vulnerability.
Affected Software
2 affected components
Smart Touch Smart Touch Call<1.0.0.8
Samsung Smart Touch Call<1.0.0.8
Event History
Dec 3, 2024
CVE Published
via MITRE·05:48 AM
Data Sourced
via MITRE·05:48 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-49417?
CVE-2024-49417 has a medium severity rating due to its potential for local exploitation.
2
How does CVE-2024-49417 affect Smart Touch Call?
CVE-2024-49417 allows local attackers to launch privileged activities through the use of implicit intents.
3
What versions of Smart Touch Call are impacted by CVE-2024-49417?
CVE-2024-49417 affects Smart Touch Call versions prior to 1.0.0.8.
4
How can I mitigate the risk of CVE-2024-49417?
To mitigate CVE-2024-49417, upgrade Smart Touch Call to version 1.0.0.8 or later.
5
Is user interaction required to exploit CVE-2024-49417?
Yes, user interaction is required to trigger the vulnerability described in CVE-2024-49417.