CVE-2022-36877
EUVD-2022-3957709.09.2022, 15:15
Exposure of Sensitive Information in FaqSymptomCardViewModel in Samsung Members prior to versions 4.3.00.11 in Global and 14.0.02.4 in China allows local attackers to access device identification via log.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| samsung | samsung_members | 𝑥 < 4.3.00.11 |
| samsung | samsung_members | 𝑥 < 14.0.02.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
- CWE-532 - Insertion of Sensitive Information into Log FileInformation written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.