Impact
The vulnerability is an improper access control flaw in Samsung SmartThings prior to version 1.8.47.24. It allows a local attacker to read sensitive information stored on the device. This issue is characterized by a lack of proper authorization checks and falls under the Access Control and Information Exposure weaknesses.
Affected Systems
Samsung Mobile SmartThings devices running firmware versions older than 1.8.47.24 are affected.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access to the device; an attacker could obtain private data but cannot compromise the entire system remotely. The risk is moderate but high enough that patching is recommended immediately.
OpenCVE Enrichment