Impact
Samsung Smart Switch lacks encryption for sensitive data in versions older than 3.7.72.6, allowing an attacker nearby to intercept data being transmitted between devices. The flaw permits the capture of confidential information without authentication, potentially revealing personal or device‑specific details to a local threat actor. This weakness can be classified as a missing encryption of sensitive data and results in a compromise of data confidentiality.
Affected Systems
The vulnerability affects Samsung Mobile’s Smart Switch application in all releases prior to version 3.7.72.6. Devices running those older versions can transmit unencrypted data during transfers, exposing the content to anyone within the same local network or physically adjacent environment.
Risk and Exploitability
The CVSS score of 7 indicates a high‑severity risk. EPSS is not available, and the issue is not listed in the CISA KEV catalog, suggesting that while the flaw is significant, it may not be actively exploited in the wild yet. The likely attack vector is a local, adjacent attacker who can observe network traffic or use a nearby wireless link to capture transmitted data. Exploitation requires no special credentials; it merely relies on proximity to the device or the network used for the transfer.
OpenCVE Enrichment