Description
Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data.
Published: 2026-08-10
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Samsung Smart Switch lacks encryption for sensitive data in versions older than 3.7.72.6, allowing an attacker nearby to intercept data being transmitted between devices. The flaw permits the capture of confidential information without authentication, potentially revealing personal or device‑specific details to a local threat actor. This weakness can be classified as a missing encryption of sensitive data and results in a compromise of data confidentiality.

Affected Systems

The vulnerability affects Samsung Mobile’s Smart Switch application in all releases prior to version 3.7.72.6. Devices running those older versions can transmit unencrypted data during transfers, exposing the content to anyone within the same local network or physically adjacent environment.

Risk and Exploitability

The CVSS score of 7 indicates a high‑severity risk. EPSS is not available, and the issue is not listed in the CISA KEV catalog, suggesting that while the flaw is significant, it may not be actively exploited in the wild yet. The likely attack vector is a local, adjacent attacker who can observe network traffic or use a nearby wireless link to capture transmitted data. Exploitation requires no special credentials; it merely relies on proximity to the device or the network used for the transfer.

Generated by OpenCVE AI on August 10, 2026 at 09:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Smart Switch to version 3.7.72.6 or later to ensure encryption is applied to transmitted data.
  • If an immediate upgrade is not possible, restrict Smart Switch usage to secure networks and consider implementing a VPN or other encrypted tunnel for any data transfers.
  • Disable or isolate adjacent network connections such as Wi‑Fi or Bluetooth during transfers to reduce the chance of a local attacker intercepting traffic.

Generated by OpenCVE AI on August 10, 2026 at 09:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Title Missing Encryption in Samsung Smart Switch Enables Local Data Interception
Weaknesses CWE-311

Mon, 10 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data.
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-08-10T17:28:14.836Z

Reserved: 2025-12-11T01:33:35.825Z

Link: CVE-2026-21079

cve-icon Vulnrichment

Updated: 2026-08-10T17:27:52.966Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T10:00:04Z

Weaknesses
  • CWE-311

    Missing Encryption of Sensitive Data