CVE Published: 09/02/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: Samsung Mobile |
Vendor: Samsung Mobile |
Product: Routine Status : PUBLISHED
CVE-2023-21441 Description
Insufficient Verification of Data Authenticity vulnerability in Routine prior to versions 2.6.30.6 in Android Q(10), 3.1.21.10 in Android R(11) and 3.5.2.23 in Android S(12) allows local attacker to access protected files via unused code.
Metrics
CVSS Version: 3.1 |
Base Score: 7.4 HIGH Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
l➤ Exploitability Metrics: Attack Vector (AV)* LOCAL Attack Complexity (AC)* HIGH Privileges Required (PR)* NONE User Interaction (UI)* REQUIRED Scope (S)* CHANGED
l➤ Impact Metrics: Confidentiality Impact (C)* HIGH Integrity Impact (I)* HIGH Availability Impact (A)* NONE
Weakness Enumeration (CWE)
CWE-ID: CWE-345 CWE Name: CWE-345: Insufficient Verification of Data Authenticity Source: Samsung Mobile
Common Attack Pattern Enumeration and Classification (CAPEC)