CVE-2023-21462

The sensitive information exposure vulnerability in Quick Share Agent prior to versions 3.5.14.18 in Android 12 and 3.5.16.20 in Android 13 allows to local attacker to access MAC address without related permission.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:samsung:quick_share:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:samsung:quick_share:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*

History

21 Nov 2024, 07:42

Type Values Removed Values Added
References () https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=03 - Vendor Advisory () https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=03 - Vendor Advisory
CVSS v2 : unknown
v3 : 3.3
v2 : unknown
v3 : 4.2

23 Mar 2023, 18:05

Type Values Removed Values Added
First Time Samsung
Google
Samsung quick Share
Google android
CPE cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
cpe:2.3:a:samsung:quick_share:*:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
References (MISC) https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=03 - (MISC) https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=03 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 3.3

Information

Published : 2023-03-16 21:15

Updated : 2024-11-21 07:42


NVD link : CVE-2023-21462

Mitre link : CVE-2023-21462

CVE.ORG link : CVE-2023-21462


JSON object : View

Products Affected

samsung

  • quick_share

google

  • android
CWE
CWE-215

Insertion of Sensitive Information Into Debugging Code

NVD-CWE-noinfo