« Volver al listado

CVE-2022-36864

Estado: ModificadaAlta (7.8)—

Improper access control and intent redirection in Samsung Email prior to 6.1.70.20 allows attacker to access specific formatted file and execute privileged behavior.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-36864",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "mobile.security@samsung.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.5
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "mobile.security@samsung.com",
      "affectedData": [
        {
          "vendor": "Samsung Mobile",
          "product": "Samsung Email",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "6.1.70.20",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-09-09T15:15:12.410",
  "references": [
    {
      "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2022&month=09",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "mobile.security@samsung.com"
    },
    {
      "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2022&month=09",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "mobile.security@samsung.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper access control and intent redirection in Samsung Email prior to 6.1.70.20 allows attacker to access specific formatted file and execute privileged behavior."
    },
    {
      "lang": "es",
      "value": "Un control de acceso inapropiado y un redireccionamiento de intentos en Samsung Email versiones anteriores a 6.1.70.20, permite a un atacante acceder a un archivo con un formato específico y ejecutar un comportamiento privilegiado"
    }
  ],
  "lastModified": "2026-06-17T04:54:04.647",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:samsung:samsung_email:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7F068755-5535-4D21-BAD7-E6E55C6FD4FB",
              "versionEndExcluding": "6.1.70.20"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "mobile.security@samsung.com"
}