« Volver al listado

CVE-2023-42545

Estado: ModificadaAlta (7.5)—

El uso de intención implícita para una vulnerabilidad de comunicación confidencial en Phone antes de las versiones 12.7.20.12 en Android 11, 13.1.48, 13.5.28 en Android 12 y 14.7.38 en Android 13 permite a los atacantes acceder a datos de ubicación.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-42545",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-42545",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-09-04T18:03:16.464601Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "mobile.security@samsung.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "mobile.security@samsung.com",
      "affectedData": [
        {
          "vendor": "Samsung Mobile",
          "product": "Phone",
          "versions": [
            {
              "status": "unaffected",
              "version": "12.7.20.12 in Android 11, 13.1.48, 13.5.28 in Android 12, and 14.7.38 in Android 13"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2023-11-07T08:15:21.027",
  "references": [
    {
      "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=11",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "mobile.security@samsung.com"
    },
    {
      "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=11",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Use of implicit intent for sensitive communication vulnerability in Phone prior to versions 12.7.20.12 in Android 11, 13.1.48, 13.5.28 in Android 12, and 14.7.38 in Android 13 allows attackers to access location data."
    },
    {
      "lang": "es",
      "value": "El uso de intención implícita para una vulnerabilidad de comunicación confidencial en Phone antes de las versiones 12.7.20.12 en Android 11, 13.1.48, 13.5.28 en Android 12 y 14.7.38 en Android 13 permite a los atacantes acceder a datos de ubicación."
    }
  ],
  "lastModified": "2026-06-17T06:24:02.733",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:samsung:phone:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5FE3D414-AB15-464A-B774-07A7437AF039",
              "versionEndExcluding": "12.7.20.12"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:samsung:android:11.0:-:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "DA3806E2-A780-4BB5-B4DC-D015D841E4C7"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:samsung:phone:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C7D1B532-E73A-4C63-95D5-8D40C2A197FB",
              "versionEndExcluding": "13.1.48"
            },
            {
              "criteria": "cpe:2.3:a:samsung:phone:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A4B9617A-1B75-45C9-B87D-0F3A451884D3",
              "versionEndExcluding": "13.5.28",
              "versionStartIncluding": "13.5.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:samsung:android:12.0:-:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D757450C-270E-4FB2-A50C-7F769FED558A"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:samsung:phone:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8623488D-66A9-4EA0-A086-09458C338422",
              "versionEndExcluding": "14.7.38"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:samsung:android:13.0:-:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A123EDB1-3048-44B0-8D4D-39A2B24B5F6B"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "mobile.security@samsung.com"
}