{ "id": "CVE-2024-20840", "sourceIdentifier": "mobile.security@samsung.com", "published": "2024-03-05T05:15:12.363", "lastModified": "2025-02-14T17:27:27.583", "vulnStatus": "Analyzed", "cveTags": [], "descriptions": [ { "lang": "en", "value": "Improper access control in Samsung Voice Recorder prior to versions 21.5.16.01 in Android 12 and Android 13, 21.4.51.02 in Android 14 allows physical attackers using hardware keyboard to use VoiceRecorder on the lock screen." }, { "lang": "es", "value": "El control de acceso inadecuado en Samsung Voice Recorder anterior a las versiones 21.5.16.01 en Android 12 y Android 13, 21.4.51.02 en Android 14 permite a atacantes f\u00edsicos que usan un teclado de hardware usar VoiceRecorder en la pantalla de bloqueo." } ], "metrics": { "cvssMetricV31": [ { "source": "mobile.security@samsung.com", "type": "Secondary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H", "baseScore": 5.7, "baseSeverity": "MEDIUM", "attackVector": "PHYSICAL", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "HIGH" }, "exploitabilityScore": 0.5, "impactScore": 5.2 }, { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "baseScore": 2.4, "baseSeverity": "LOW", "attackVector": "PHYSICAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW" }, "exploitabilityScore": 0.9, "impactScore": 1.4 } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "NVD-CWE-Other" } ] } ], "configurations": [ { "operator": "AND", "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:samsung:voice_recorder:*:*:*:*:*:*:*:*", "versionEndExcluding": "21.5.16.01", "matchCriteriaId": "E0E061AA-A319-428F-A9B7-8D492BC35968" } ] }, { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": false, "criteria": "cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*", "matchCriteriaId": "F8FB8EE9-FC56-4D5E-AE55-A5967634740C" }, { "vulnerable": false, "criteria": "cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*", "matchCriteriaId": "879FFD0C-9B38-4CAA-B057-1086D794D469" } ] } ] }, { "operator": "AND", "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:samsung:voice_recorder:*:*:*:*:*:*:*:*", "versionEndExcluding": "21.4.51.02", "matchCriteriaId": "702AF91C-B029-406C-B4B3-2B9649D293BA" } ] }, { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": false, "criteria": "cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*", "matchCriteriaId": "2700BCC5-634D-4EC6-AB67-5B678D5F951D" } ] } ] } ], "references": [ { "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=03", "source": "mobile.security@samsung.com", "tags": [ "Vendor Advisory" ] }, { "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=03", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] } ] }