mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-05-28 01:02:25 +00:00
52 lines
1.8 KiB
JSON
52 lines
1.8 KiB
JSON
{
|
|
"id": "CVE-2024-20854",
|
|
"sourceIdentifier": "mobile.security@samsung.com",
|
|
"published": "2024-04-02T03:15:10.870",
|
|
"lastModified": "2024-11-21T08:53:16.940",
|
|
"vulnStatus": "Awaiting Analysis",
|
|
"cveTags": [],
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "Improper handling of insufficient privileges vulnerability in Samsung Camera prior to versions 12.1.0.31 in Android 12, 13.1.02.07 in Android 13, and 14.0.01.06 in Android 14 allows local attackers to access image data."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "El manejo inadecuado de la vulnerabilidad de privilegios insuficientes en Samsung Camera antes de las versiones 12.1.0.31 en Android 12, 13.1.02.07 en Android 13 y 14.0.01.06 en Android 14 permite a atacantes locales acceder a datos de im\u00e1genes."
|
|
}
|
|
],
|
|
"metrics": {
|
|
"cvssMetricV31": [
|
|
{
|
|
"source": "mobile.security@samsung.com",
|
|
"type": "Secondary",
|
|
"cvssData": {
|
|
"version": "3.1",
|
|
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
|
|
"baseScore": 5.9,
|
|
"baseSeverity": "MEDIUM",
|
|
"attackVector": "LOCAL",
|
|
"attackComplexity": "LOW",
|
|
"privilegesRequired": "NONE",
|
|
"userInteraction": "NONE",
|
|
"scope": "UNCHANGED",
|
|
"confidentialityImpact": "LOW",
|
|
"integrityImpact": "LOW",
|
|
"availabilityImpact": "LOW"
|
|
},
|
|
"exploitabilityScore": 2.5,
|
|
"impactScore": 3.4
|
|
}
|
|
]
|
|
},
|
|
"references": [
|
|
{
|
|
"url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=04",
|
|
"source": "mobile.security@samsung.com"
|
|
},
|
|
{
|
|
"url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=04",
|
|
"source": "af854a3a-2127-422b-91ae-364da2661108"
|
|
}
|
|
]
|
|
} |