CVE-2022-39893
Estado: ModificadaBaja (3.3)—
Sensitive information exposure vulnerability in FmmBaseModel in Galaxy Buds Pro Manage prior to version 4.1.22092751 allows local attackers with log access permission to get device identifier data through device log.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Puntuación base: 3.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.22%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-532
- CWE-532
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-39893",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2022-39893",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-05-01T19:29:13.594518Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "mobile.security@samsung.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 3.3,
"attackVector": "LOCAL",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 1.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 3.3,
"attackVector": "LOCAL",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "mobile.security@samsung.com",
"affectedData": [
{
"vendor": "Samsung Mobile",
"product": "Galaxy Buds Pro Manager",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "4.1.22092751",
"versionType": "custom"
}
]
}
]
}
],
"published": "2022-11-09T22:15:18.977",
"references": [
{
"url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2022&month=11",
"tags": [
"Vendor Advisory"
],
"source": "mobile.security@samsung.com"
},
{
"url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2022&month=11",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "mobile.security@samsung.com",
"description": [
{
"lang": "en",
"value": "CWE-532"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-532"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Sensitive information exposure vulnerability in FmmBaseModel in Galaxy Buds Pro Manage prior to version 4.1.22092751 allows local attackers with log access permission to get device identifier data through device log."
},
{
"lang": "es",
"value": "Vulnerabilidad de exposición de información confidencial en FmmBaseModel en Galaxy Buds Pro Manage anterior a la versión 4.1.22092751 permite a atacantes locales con permiso de acceso al registro obtener datos de identificación del dispositivo a través del registro del dispositivo."
}
],
"lastModified": "2026-06-17T04:58:30.430",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:samsung:galaxy_buds_pro_manage:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2F42386F-B2F1-4129-8853-6C832C4CF12B",
"versionEndExcluding": "4.1.22092751"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "mobile.security@samsung.com"
}