Samsung
Samsung Smartthings: vulnerabilidades y CVE
Samsung Smartthings tiene 18 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE18
Últimos 12 meses1
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-21084 | Media (6.9) | 0.13% | — | 10 ago 2026 | Improper access control in SmartThings prior to version 1.8.47.24 allows local attackers to access sensitive information. |
| CVE-2025-2233 | Alta (8.8) | 0.76% | — | 11 mar 2025 | Samsung SmartThings Improper Verification of Cryptographic Signature Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of… |
| CVE-2024-49416 | Media (5.5) | 0.13% | — | 3 dic 2024 | Use of implicit intent for sensitive communication in SmartThings prior to version 1.8.21 allows local attackers to get sensitive information. |
| CVE-2024-34596 | Alta (7.5) | 0.48% | — | 2 jul 2024 | Improper authentication in SmartThings prior to version 1.8.17 allows remote attackers to bypass the expiration date for members set by the owner. |
| CVE-2024-20852 | Baja (3.3) | 0.14% | — | 2 abr 2024 | Improper verification of intent by broadcast receiver vulnerability in SmartThings prior to version 1.8.13.22 allows local attackers to access testing configuration. |
| CVE-2022-39871 | Alta (7.5) | 0.37% | — | 7 oct 2022 | Improper access control vulnerability cloudNotificationManager.java in SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcasts. |
| CVE-2022-39870 | Alta (7.5) | 0.37% | — | 7 oct 2022 | Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via PUSH_MESSAGE_RECEIVED broadcast. |
| CVE-2022-39869 | Alta (7.5) | 0.37% | — | 7 oct 2022 | Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via REMOVE_PERSISTENT_BANNER broadcast. |
| CVE-2022-39868 | Alta (7.5) | 0.37% | — | 7 oct 2022 | Improper access control vulnerability in GedSamsungAccount.kt SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast. |
| CVE-2022-39867 | Alta (7.5) | 0.37% | — | 7 oct 2022 | Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via SHOW_PERSISTENT_BANNER broadcast. |
| CVE-2022-39866 | Alta (7.5) | 0.37% | — | 7 oct 2022 | Improper access control vulnerability in RegisteredEventMediator.kt SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast. |
| CVE-2022-39865 | Alta (7.5) | 0.37% | — | 7 oct 2022 | Improper access control vulnerability in ContentsSharingActivity.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast. |
| CVE-2022-39864 | Alta (7.5) | 0.35% | — | 7 oct 2022 | Improper access control vulnerability in WifiSetupLaunchHelper in SmartThings prior to version 1.7.89.25 allows attackers to access sensitive information via implicit intent. |
| CVE-2022-30749 | Alta (7.8) | 0.18% | — | 7 jun 2022 | Improper access control vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to add arbitrary smart devices by bypassing login activity. |
| CVE-2022-30747 | Media (5.5) | 0.19% | — | 7 jun 2022 | PendingIntent hijacking vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to access files without permission via implicit Intent. |
| CVE-2022-30746 | Alta (7.5) | 0.87% | — | 7 jun 2022 | Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely using javascript interface API. |
| CVE-2021-25508 | Crítica (9.8) | 0.83% | — | 5 nov 2021 | Improper privilege management vulnerability in API Key used in SmartThings prior to 1.7.73.22 allows an attacker to abuse the API key without limitation. |
| CVE-2021-25378 | Media (5.3) | 0.97% | — | 9 abr 2021 | Improper access control of certain port in SmartThings prior to version 1.7.63.6 allows remote temporary denial of service. |