CVE-2023-42545
Status: ModifiedHigh (7.5)—
Use of implicit intent for sensitive communication vulnerability in Phone prior to versions 12.7.20.12 in Android 11, 13.1.48, 13.5.28 in Android 12, and 14.7.38 in Android 13 allows attackers to access location data.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Base score: 7.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.43%
- Percentile among all scored CVEs: 36
- Score date: 10/8/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- NVD-CWE-noinfo
References
Raw JSON (NVD)
Show
{
"id": "CVE-2023-42545",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-42545",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-09-04T18:03:16.464601Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "mobile.security@samsung.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "mobile.security@samsung.com",
"affectedData": [
{
"vendor": "Samsung Mobile",
"product": "Phone",
"versions": [
{
"status": "unaffected",
"version": "12.7.20.12 in Android 11, 13.1.48, 13.5.28 in Android 12, and 14.7.38 in Android 13"
}
],
"defaultStatus": "affected"
}
]
}
],
"published": "2023-11-07T08:15:21.027",
"references": [
{
"url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=11",
"tags": [
"Vendor Advisory"
],
"source": "mobile.security@samsung.com"
},
{
"url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=11",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Use of implicit intent for sensitive communication vulnerability in Phone prior to versions 12.7.20.12 in Android 11, 13.1.48, 13.5.28 in Android 12, and 14.7.38 in Android 13 allows attackers to access location data."
},
{
"lang": "es",
"value": "El uso de intención implícita para una vulnerabilidad de comunicación confidencial en Phone antes de las versiones 12.7.20.12 en Android 11, 13.1.48, 13.5.28 en Android 12 y 14.7.38 en Android 13 permite a los atacantes acceder a datos de ubicación."
}
],
"lastModified": "2026-06-17T06:24:02.733",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:samsung:phone:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5FE3D414-AB15-464A-B774-07A7437AF039",
"versionEndExcluding": "12.7.20.12"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:samsung:android:11.0:-:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "DA3806E2-A780-4BB5-B4DC-D015D841E4C7"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:samsung:phone:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C7D1B532-E73A-4C63-95D5-8D40C2A197FB",
"versionEndExcluding": "13.1.48"
},
{
"criteria": "cpe:2.3:a:samsung:phone:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A4B9617A-1B75-45C9-B87D-0F3A451884D3",
"versionEndExcluding": "13.5.28",
"versionStartIncluding": "13.5.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:samsung:android:12.0:-:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D757450C-270E-4FB2-A50C-7F769FED558A"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:samsung:phone:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8623488D-66A9-4EA0-A086-09458C338422",
"versionEndExcluding": "14.7.38"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:samsung:android:13.0:-:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A123EDB1-3048-44B0-8D4D-39A2B24B5F6B"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "mobile.security@samsung.com"
}