« Volver al listado

CVE-2022-36829

Estado: ModificadaMedia (5.5)—

PendingIntent hijacking vulnerability in releaseAlarm in Charm by Samsung prior to version 1.2.3 allows local attackers to access files without permission via implicit intent.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-36829",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "mobile.security@samsung.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.2,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.5
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "mobile.security@samsung.com",
      "affectedData": [
        {
          "vendor": "Samsung Mobile",
          "product": "Charm by Samsung",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "1.2.3",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-08-05T16:15:14.703",
  "references": [
    {
      "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2022&month=08",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "mobile.security@samsung.com"
    },
    {
      "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2022&month=08",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "mobile.security@samsung.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-927"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "PendingIntent hijacking vulnerability in releaseAlarm in Charm by Samsung prior to version 1.2.3 allows local attackers to access files without permission via implicit intent."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de secuestro de PendingIntent en releaseAlarm en Charm de Samsung versiones anteriores a 1.2.3, permite a atacantes locales acceder a archivos sin permiso por medio de una intención implícita"
    }
  ],
  "lastModified": "2026-06-17T04:54:00.840",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:samsung:charm_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A261E8CE-5B3F-4BF5-BC15-B3B515409685",
              "versionEndExcluding": "1.2.3"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:samsung:charm:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "CD7C4ABA-373B-4DD2-9E09-832E6477CC09"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "mobile.security@samsung.com"
}