Improper handling of insufficient permissions in Samsung Assistant prior to version 9.1.00.7 allows remote attackers to access location data. User interaction is required for triggering this vulnerability.
History

Thu, 05 Sep 2024 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Samsung
Samsung assistant
Weaknesses CWE-276
CPEs cpe:2.3:a:samsung:assistant:*:*:*:*:*:*:*:*
Vendors & Products Samsung
Samsung assistant

Wed, 04 Sep 2024 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 04 Sep 2024 05:45:00 +0000

Type Values Removed Values Added
Description Improper handling of insufficient permissions in Samsung Assistant prior to version 9.1.00.7 allows remote attackers to access location data. User interaction is required for triggering this vulnerability.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published: 2024-09-04T05:32:47.507Z

Updated: 2024-09-04T12:44:31.149Z

Reserved: 2024-05-07T04:43:27.846Z

Link: CVE-2024-34661

cve-icon Vulnrichment

Updated: 2024-09-04T12:44:27.549Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-04T06:15:17.003

Modified: 2024-09-05T17:57:44.563

Link: CVE-2024-34661

cve-icon Redhat

No data.