Vulnerabilidades em Samsung Mobile

1.391 resultados
Análise Vexday

Samsung Mobile acumula 1.316 CVEs catalogadas, com 13 confirmadas em exploração ativa pelo CISA KEV — uma taxa 2,2 vezes acima da média geral do catálogo, o que indica exposição operacional relevante e exige atenção prioritária na gestão de patches. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), sugerindo fragilidades sistemáticas no tratamento de dados externos que tendem a gerar superfícies amplas de ataque. A CVE mais perigosa em exploração ativa no momento é CVE-2025-21042, com escore EPSS de 0,1161, enquanto 34 novas vulnerabilidades surgiram nos últimos 90 dias, sinalizando um ritmo de descoberta contínuo que demanda monitoramento frequente. Com apenas 3 CVEs acompanhadas de PoC pública e EPSS máximo observado de 0,1289, o risco de exploração massiva imediata é moderado, mas a combinação de falhas ativas confirmadas e volume crescente de novas entradas justifica ciclos curtos de atualização de firmware em ambientes corporativos.

CVE-2022-39866MEDIUMImproper access control vulnerability in RegisteredEventMediator.kt SmartThings prior to version 1.7.89.0 allows attackers to access sensitiEPSS 0.4%CVE-2022-39871MEDIUMImproper access control vulnerability cloudNotificationManager.java in SmartThings prior to version 1.7.89.0 allows attackers to access sensEPSS 0.4%CVE-2022-39869MEDIUMImproper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensEPSS 0.4%CVE-2023-30727MEDIUMImproper access control vulnerability in SecSettings prior to SMR Oct-2023 Release 1 allows attackers to enable Wi-Fi and connect arbitrary EPSS 0.4%CVE-2024-20816HIGHImproper authentication vulnerability in onCharacteristicWriteRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackEPSS 0.4%CVE-2021-25440Improper access control vulnerability in FactoryCameraFB prior to version 3.4.74 allows untrusted applications to access arbitrary files witEPSS 0.4%CVE-2021-25395MEDIUMA race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilEPSS 0.4%KEVCVE-2022-27573MEDIUMImproper input validation vulnerability in parser_infe and sheifd_find_itemIndexin fuctions of libsimba library prior to SMR Apr-2022 ReleasEPSS 0.4%CVE-2022-39863LOWIntent redirection vulnerability in Samsung Account prior to version 13.5.01.3 allows attackers to access content providers without permissiEPSS 0.4%CVE-2026-21075MEDIUMImproper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to access sensitive informEPSS 0.4%CVE-2022-33719HIGHImproper input validation in baseband prior to SMR Aug-2022 Release 1 allows attackers to cause integer overflow to heap overflow.EPSS 0.4%CVE-2022-39877MEDIUMImproper access control vulnerability in ProfileSharingAccount in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in AEPSS 0.4%CVE-2023-42561HIGHHeap out-of-bounds write vulnerability in bootloader prior to SMR Dec-2023 Release 1 allows a physical attacker to execute arbitrary code.EPSS 0.4%CVE-2022-39864LOWImproper access control vulnerability in WifiSetupLaunchHelper in SmartThings prior to version 1.7.89.25 allows attackers to access sensitivEPSS 0.4%CVE-2024-20829MEDIUMMissing proper interaction for opening deeplink in Samsung Internet prior to version v24.0.0.0 allows remote attackers to open an applicatioEPSS 0.3%CVE-2022-28779MEDIUMUncontrolled search path element vulnerability in Samsung Android USB Driver windows installer program prior to version 1.7.50 allows attackEPSS 0.3%CVE-2022-36876LOWImproper authorization in UPI payment in Samsung Pass prior to version 4.0.04.10 allows physical attackers to access account list without auEPSS 0.3%CVE-2022-36851LOWImproper access control vulnerability in Samsung pass prior to version 4.0.03.1 allow physical attackers to access data of Samsung pass on aEPSS 0.3%CVE-2024-49421MEDIUMPath traversal in Quick Share Agent prior to version 3.5.14.47 in Android 12, 3.5.19.41 in Android 13, and 3.5.19.42 in Android 14 allows adEPSS 0.3%CVE-2024-34661MEDIUMImproper handling of insufficient permissions in Samsung Assistant prior to version 9.1.00.7 allows remote attackers to access location dataEPSS 0.3%