Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely using javascript interface API.
References
Link | Resource |
---|---|
https://security.samsungmobile.com/serviceWeb.smsb?year=2022&month=6 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: Samsung Mobile
Published: 2022-06-07T18:20:19
Updated: 2022-06-07T18:20:19
Reserved: 2022-05-16T00:00:00
Link: CVE-2022-30746
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-06-07T19:15:10.790
Modified: 2023-06-29T14:43:22.200
Link: CVE-2022-30746
JSON object: View
Redhat Information
No data.