Vulnerabilidades em Samsung Mobile

1.391 resultados
Análise Vexday

Samsung Mobile acumula 1.316 CVEs catalogadas, com 13 confirmadas em exploração ativa pelo CISA KEV — uma taxa 2,2 vezes acima da média geral do catálogo, o que indica exposição operacional relevante e exige atenção prioritária na gestão de patches. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), sugerindo fragilidades sistemáticas no tratamento de dados externos que tendem a gerar superfícies amplas de ataque. A CVE mais perigosa em exploração ativa no momento é CVE-2025-21042, com escore EPSS de 0,1161, enquanto 34 novas vulnerabilidades surgiram nos últimos 90 dias, sinalizando um ritmo de descoberta contínuo que demanda monitoramento frequente. Com apenas 3 CVEs acompanhadas de PoC pública e EPSS máximo observado de 0,1289, o risco de exploração massiva imediata é moderado, mas a combinação de falhas ativas confirmadas e volume crescente de novas entradas justifica ciclos curtos de atualização de firmware em ambientes corporativos.

CVE-2022-24927MEDIUMImproper privilege management vulnerability in Samsung Video Player prior to version 7.3.15.30 allows attackers to execute video files withoEPSS 0.3%CVE-2023-42554MEDIUMImproper Authentication vulnerabiity in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication.EPSS 0.3%CVE-2023-30703LOWImproper URL validation vulnerability in Samsung Members prior to version 14.0.07.1 allows attackers to access sensitive information.EPSS 0.3%CVE-2021-25525LOWImproper check or handling of exception conditions vulnerability in Samsung Pay (US only) prior to version 4.0.65 allows attacker to use NFCEPSS 0.3%CVE-2023-42571HIGHAbuse of remote unlock in Find My Mobile prior to version 7.3.13.4 allows physical attacker to unlock the device remotely by resetting the SEPSS 0.3%CVE-2022-28543MEDIUMPath traversal vulnerability in Samsung Flow prior to version 4.8.07.4 allows local attackers to read arbitrary files as Samsung Flow permisEPSS 0.3%CVE-2023-42559MEDIUMImproper exception management vulnerability in Knox Guard prior to SMR Dec-2023 Release 1 allows Knox Guard lock bypass via changing system EPSS 0.3%CVE-2022-27835HIGHImproper boundary check in UWB firmware prior to SMR Apr-2022 Release 1 allows arbitrary memory write.EPSS 0.3%CVE-2025-20949MEDIUMPath traversal vulnerability in Samsung Members prior to version 5.0.00.11 allows attackers to read and write arbitrary file with the privilEPSS 0.3%CVE-2024-20865MEDIUMAuthentication bypass in bootloader prior to SMR May-2024 Release 1 allows physical attackers to flash arbitrary images.EPSS 0.3%CVE-2026-21092HIGHPath traversal in ImsService prior to SMR Sep-2026 Release 1 allows remote attackers to create image files with system server privilege.EPSS 0.3%CVE-2026-20999HIGHAuthentication bypass by replay in Smart Switch prior to version 3.7.69.15 allows remote attackers to trigger privileged functions.EPSS 0.3%CVE-2026-20982MEDIUMPath traversal in ShortcutService prior to SMR Feb-2026 Release 1 allows privileged local attacker to create file with system privilege.EPSS 0.3%CVE-2025-20968HIGHImproper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in EPSS 0.3%CVE-2023-21467MEDIUMError in 3GPP specification implementation in Exynos baseband prior to SMR Apr-2023 Release 1 allows incorrect handling of unencrypted messaEPSS 0.3%CVE-2023-21505MEDIUMImproper access control in Samsung Core Service prior to version 2.1.00.36 allows attacker to write arbitrary file in sandbox.EPSS 0.3%CVE-2023-42577MEDIUMImproper Access Control in Samsung Voice Recorder prior to versions 21.4.15.01 in Android 12 and Android 13, 21.4.50.17 in Android 14 allowsEPSS 0.3%CVE-2021-25516MEDIUMAn improper check or handling of exceptional conditions in Exynos baseband prior to SMR Dec-2021 Release 1 allows attackers to track locatioEPSS 0.3%CVE-2022-39915LOWImproper access control vulnerability in Calendar prior to versions 11.6.08.0 in Android Q(10), 12.2.11.3000 in Android R(11), 12.3.07.2000 EPSS 0.3%CVE-2022-27824MEDIUMImproper size check of in sapefd_parse_meta_DESCRIPTION function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bEPSS 0.3%