Impact
Samsung Health before version 7.0.0 contains a relative path traversal vulnerability that exposes sensitive data to unauthenticated local users. The CVE does not specify how the flaw is triggered, but a user or process with local access could cause the application to read files outside its intended directory, potentially revealing personal health records and other confidential information. The weakness is a classic path traversal flaw.
Affected Systems
The affected product is Samsung Health on Samsung Mobile devices. Versions earlier than 7.0.0 are impacted; no specific patch release versions are listed beyond this threshold.
Risk and Exploitability
The vulnerability has a CVSS score of 6.9, indicating a medium severity impact. EPSS score is reported as < 1%, reflecting a very low but non-zero probability of exploitation. The flaw is not listed in the CISA KEV catalog, suggesting no widespread exploitation. Based on the description, the exact attack vector is not specified, but the vulnerability implies that local access is needed to exploit the path traversal. Deployment in a local context could allow an attacker with device access to read arbitrary files, thereby compromising confidentiality, though remote exploitation is unlikely based on current information.
OpenCVE Enrichment