CVE-2024-34597

Improper input validation in Samsung Health prior to version 6.27.0.113 allows local attackers to write arbitrary document files to the sandbox of Samsung Health. User interaction is required for triggering this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:samsung:health:*:*:*:*:*:*:*:*

History

21 Nov 2024, 09:19

Type Values Removed Values Added
References () https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=07 - Vendor Advisory () https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=07 - Vendor Advisory
CVSS v2 : unknown
v3 : 3.3
v2 : unknown
v3 : 4.4

02 Jul 2024, 18:04

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 4.4
v2 : unknown
v3 : 3.3
First Time Samsung
Samsung health
References () https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=07 - () https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=07 - Vendor Advisory
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:samsung:health:*:*:*:*:*:*:*:*

02 Jul 2024, 12:09

Type Values Removed Values Added
Summary
  • (es) La validación de entrada incorrecta en Samsung Health anterior a la versión 6.27.0.113 permite a atacantes locales escribir archivos de documentos arbitrarios en la sandbox de Samsung Health. Se requiere la interacción del usuario para activar esta vulnerabilidad.

02 Jul 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-02 10:15

Updated : 2024-11-21 09:19


NVD link : CVE-2024-34597

Mitre link : CVE-2024-34597

CVE.ORG link : CVE-2024-34597


JSON object : View

Products Affected

samsung

  • health