CVE-2024-34597

Improper input validation in Samsung Health prior to version 6.27.0.113 allows local attackers to write arbitrary document files to the sandbox of Samsung Health. User interaction is required for triggering this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:samsung:health:*:*:*:*:*:*:*:*

History

02 Jul 2024, 18:04

Type Values Removed Values Added
CPE cpe:2.3:a:samsung:health:*:*:*:*:*:*:*:*
References () https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=07 - () https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=07 - Vendor Advisory
CVSS v2 : unknown
v3 : 4.4
v2 : unknown
v3 : 3.3
CWE NVD-CWE-noinfo
First Time Samsung
Samsung health

02 Jul 2024, 12:09

Type Values Removed Values Added
Summary
  • (es) La validación de entrada incorrecta en Samsung Health anterior a la versión 6.27.0.113 permite a atacantes locales escribir archivos de documentos arbitrarios en la sandbox de Samsung Health. Se requiere la interacción del usuario para activar esta vulnerabilidad.

02 Jul 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-02 10:15

Updated : 2024-07-02 18:04


NVD link : CVE-2024-34597

Mitre link : CVE-2024-34597

CVE.ORG link : CVE-2024-34597


JSON object : View

Products Affected

samsung

  • health