Description
Insufficient verification of data authenticity in Smart Switch trouble scanning mode prior to version 3.7.72.6 allows adjacent attackers to spoof device identity.
Published: 2026-08-10
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Smart Switch application on Samsung Mobile devices has a flaw in its trouble scanning mode before version 3.7.72.6. It does not verify the authenticity of data received during a trouble scan, allowing an attacker who is physically adjacent to the target device to spoof its identity. This can make the device appear as a different device, potentially misleading users or other applications that rely on the identity information. No additional exploitation or integrity compromise is described in the advisory.

Affected Systems

The affected product is Samsung Mobile's Smart Switch. All releases prior to version 3.7.72.6 are vulnerable. Users who employ the trouble scanning feature with these older versions are at risk.

Risk and Exploitability

The CVSS score of 4.7 indicates a moderate risk. The EPSS score is less than 1%, indicating a low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The attack likely requires local or adjacent access because it uses the trouble scanning mode performed during device‑to‑device transfers. No network or privilege escalation is required beyond proximity to the device.

Generated by OpenCVE AI on August 10, 2026 at 20:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Smart Switch to version 3.7.72.6 or later, which introduces proper data authenticity checks.
  • If an upgrade is not possible immediately, disable or restrict the trouble scanning feature to prevent identity spoofing.
  • Refer to Samsung Mobile's security advisory and monitor for any further patch or guidance.

Generated by OpenCVE AI on August 10, 2026 at 20:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Smart Switch Identity Spoofing via Trouble Scanning Mode
Weaknesses CWE-285
CWE-346

Mon, 10 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-345
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Title Smart Switch Identity Spoofing via Trouble Scanning Mode
Weaknesses CWE-285
CWE-346

Mon, 10 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description Insufficient verification of data authenticity in Smart Switch trouble scanning mode prior to version 3.7.72.6 allows adjacent attackers to spoof device identity.
References
Metrics cvssV4_0

{'score': 4.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-08-10T17:25:38.837Z

Reserved: 2025-12-11T01:33:35.825Z

Link: CVE-2026-21078

cve-icon Vulnrichment

Updated: 2026-08-10T17:21:15.064Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T21:00:04Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity