Impact
The Smart Switch application on Samsung Mobile devices has a flaw in its trouble scanning mode before version 3.7.72.6. It does not verify the authenticity of data received during a trouble scan, allowing an attacker who is physically adjacent to the target device to spoof its identity. This can make the device appear as a different device, potentially misleading users or other applications that rely on the identity information. No additional exploitation or integrity compromise is described in the advisory.
Affected Systems
The affected product is Samsung Mobile's Smart Switch. All releases prior to version 3.7.72.6 are vulnerable. Users who employ the trouble scanning feature with these older versions are at risk.
Risk and Exploitability
The CVSS score of 4.7 indicates a moderate risk. The EPSS score is less than 1%, indicating a low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The attack likely requires local or adjacent access because it uses the trouble scanning mode performed during device‑to‑device transfers. No network or privilege escalation is required beyond proximity to the device.
OpenCVE Enrichment