CVE-2023-42545
Estado: ModificadaAlta (7.5)—
El uso de intención implícita para una vulnerabilidad de comunicación confidencial en Phone antes de las versiones 12.7.20.12 en Android 11, 13.1.48, 13.5.28 en Android 12 y 14.7.38 en Android 13 permite a los atacantes acceder a datos de ubicación.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.43%
- Percentil entre todas las CVEs puntuadas: 36
- Fecha de la puntuación: 8/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-noinfo
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-42545",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-42545",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-09-04T18:03:16.464601Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "mobile.security@samsung.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "mobile.security@samsung.com",
"affectedData": [
{
"vendor": "Samsung Mobile",
"product": "Phone",
"versions": [
{
"status": "unaffected",
"version": "12.7.20.12 in Android 11, 13.1.48, 13.5.28 in Android 12, and 14.7.38 in Android 13"
}
],
"defaultStatus": "affected"
}
]
}
],
"published": "2023-11-07T08:15:21.027",
"references": [
{
"url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=11",
"tags": [
"Vendor Advisory"
],
"source": "mobile.security@samsung.com"
},
{
"url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=11",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Use of implicit intent for sensitive communication vulnerability in Phone prior to versions 12.7.20.12 in Android 11, 13.1.48, 13.5.28 in Android 12, and 14.7.38 in Android 13 allows attackers to access location data."
},
{
"lang": "es",
"value": "El uso de intención implícita para una vulnerabilidad de comunicación confidencial en Phone antes de las versiones 12.7.20.12 en Android 11, 13.1.48, 13.5.28 en Android 12 y 14.7.38 en Android 13 permite a los atacantes acceder a datos de ubicación."
}
],
"lastModified": "2026-06-17T06:24:02.733",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:samsung:phone:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5FE3D414-AB15-464A-B774-07A7437AF039",
"versionEndExcluding": "12.7.20.12"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:samsung:android:11.0:-:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "DA3806E2-A780-4BB5-B4DC-D015D841E4C7"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:samsung:phone:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C7D1B532-E73A-4C63-95D5-8D40C2A197FB",
"versionEndExcluding": "13.1.48"
},
{
"criteria": "cpe:2.3:a:samsung:phone:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A4B9617A-1B75-45C9-B87D-0F3A451884D3",
"versionEndExcluding": "13.5.28",
"versionStartIncluding": "13.5.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:samsung:android:12.0:-:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D757450C-270E-4FB2-A50C-7F769FED558A"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:samsung:phone:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8623488D-66A9-4EA0-A086-09458C338422",
"versionEndExcluding": "14.7.38"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:samsung:android:13.0:-:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A123EDB1-3048-44B0-8D4D-39A2B24B5F6B"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "mobile.security@samsung.com"
}