Impact
The vulnerability arises from improper input validation in Samsung Mobile Smart Switch versions prior to 3.7.72.6, which enables attackers located adjacent to the device to read sensitive data stored on the device. This flaw can compromise the confidentiality of user data, exposing potentially personal or corporate information without affecting integrity or availability.
Affected Systems
Samsung Mobile Smart Switch products on mobile devices running firmware versions older than 3.7.72.6.
Risk and Exploitability
The CVSS score of 6.8 indicates a moderate severity level. With the EPSS score unavailable, the exploitation likelihood remains uncertain, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local, requiring proximity to the device as the description references adjacent attackers. An attacker could leverage this weakness to read sensitive data but would not gain remote code execution or broader system compromise.
OpenCVE Enrichment