- Description
- Improper input validation in Samsung Health prior to version 6.27.0.113 allows local attackers to write arbitrary document files to the sandbox of Samsung Health. User interaction is required for triggering this vulnerability.
- Source
- mobile.security@samsung.com
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 3.3
- Impact score
- 1.4
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- Severity
- LOW
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:samsung:health:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "72946B1F-4F1C-4AEF-BB97-6E91D10365C5",
"versionEndExcluding": "6.27.0.113"
}
],
"operator": "OR"
}
]
}
]