CVE-2023-21445
EUVD-2023-2561309.02.2023, 19:15
Improper access control vulnerability in MyFiles prior to versions 12.2.09 in Android R(11), 13.1.03.501 in Android S(12) and 14.1.00.422 in Android T(13) allows local attacker to write file with MyFiles privilege via implicit intent.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| samsung | android | 11.0 |
| samsung | android | 11.0:smr-apr-2021-r1 |
| samsung | android | 11.0:smr-apr-2022-r1 |
| samsung | android | 11.0:smr-apr-2023-r1 |
| samsung | android | 11.0:smr-aug-2021-r1 |
| samsung | android | 11.0:smr-aug-2022-r1 |
| samsung | android | 11.0:smr-aug-2023-r1 |
| samsung | android | 11.0:smr-dec-2020-r1 |
| samsung | android | 11.0:smr-dec-2021-r1 |
| samsung | android | 11.0:smr-dec-2022-r1 |
| samsung | android | 11.0:smr-dec-2023-r1 |
| samsung | android | 11.0:smr-feb-2021-r1 |
| samsung | android | 11.0:smr-feb-2022-r1 |
| samsung | android | 11.0:smr-feb-2023-r1 |
| samsung | android | 11.0:smr-jan-2021-r1 |
| samsung | android | 11.0:smr-jan-2022-r1 |
| samsung | android | 11.0:smr-jul-2021-r1 |
| samsung | android | 11.0:smr-jul-2022-r1 |
| samsung | android | 11.0:smr-jul-2023-r1 |
| samsung | android | 11.0:smr-jun-2021-r1 |
| samsung | android | 11.0:smr-jun-2022-r1 |
| samsung | android | 11.0:smr-jun-2023-r1 |
| samsung | android | 11.0:smr-mar-2021-r1 |
| samsung | android | 11.0:smr-mar-2022-r1 |
| samsung | android | 11.0:smr-mar-2023-r1 |
| samsung | android | 11.0:smr-may-2021-r1 |
| samsung | android | 11.0:smr-may-2022-r1 |
| samsung | android | 11.0:smr-may-2023-r1 |
| samsung | android | 11.0:smr-nov-2021-r1 |
| samsung | android | 11.0:smr-nov-2022-r1 |
| samsung | android | 11.0:smr-nov-2023-r1 |
| samsung | android | 11.0:smr-oct-2021-r1 |
| samsung | android | 11.0:smr-oct-2022-r1 |
| samsung | android | 11.0:smr-oct-2023-r1 |
| samsung | android | 11.0:smr-sep-2021-r1 |
| samsung | android | 11.0:smr-sep-2022-r1 |
| samsung | android | 11.0:smr-sep-2023-r1 |
| samsung | android | 12.0 |
| samsung | android | 12.0:smr-apr-2022-r1 |
| samsung | android | 12.0:smr-apr-2023-r1 |
| samsung | android | 12.0:smr-aug-2022-r1 |
| samsung | android | 12.0:smr-aug-2023-r1 |
| samsung | android | 12.0:smr-dec-2021-r1 |
| samsung | android | 12.0:smr-dec-2022-r1 |
| samsung | android | 12.0:smr-dec-2023-r1 |
| samsung | android | 12.0:smr-feb-2022-r1 |
| samsung | android | 12.0:smr-feb-2023-r1 |
| samsung | android | 12.0:smr-jan-2022-r1 |
| samsung | android | 12.0:smr-jul-2022-r1 |
| samsung | android | 12.0:smr-jul-2023-r1 |
| samsung | android | 12.0:smr-jun-2022-r1 |
| samsung | android | 12.0:smr-jun-2023-r1 |
| samsung | android | 12.0:smr-mar-2022-r1 |
| samsung | android | 12.0:smr-mar-2023-r1 |
| samsung | android | 12.0:smr-may-2022-r1 |
| samsung | android | 12.0:smr-may-2023-r1 |
| samsung | android | 12.0:smr-nov-2021-r1 |
| samsung | android | 12.0:smr-nov-2022-r1 |
| samsung | android | 12.0:smr-nov-2023-r1 |
| samsung | android | 12.0:smr-oct-2022-r1 |
| samsung | android | 12.0:smr-oct-2023-r1 |
| samsung | android | 12.0:smr-sep-2022-r1 |
| samsung | android | 12.0:smr-sep-2023-r1 |
| samsung | android | 13.0 |
| samsung | android | 13.0:smr-apr-2023-r1 |
| samsung | android | 13.0:smr-aug-2023-r1 |
| samsung | android | 13.0:smr-dec-2022-r1 |
| samsung | android | 13.0:smr-dec-2023-r1 |
| samsung | android | 13.0:smr-feb-2023-r1 |
| samsung | android | 13.0:smr-jul-2023-r1 |
| samsung | android | 13.0:smr-jun-2023-r1 |
| samsung | android | 13.0:smr-mar-2023-r1 |
| samsung | android | 13.0:smr-may-2023-r1 |
| samsung | android | 13.0:smr-nov-2022-r1 |
| samsung | android | 13.0:smr-nov-2023-r1 |
| samsung | android | 13.0:smr-oct-2022-r1 |
| samsung | android | 13.0:smr-oct-2023-r1 |
| samsung | android | 13.0:smr-sep-2023-r1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-284 - Improper Access ControlThe software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
- CWE-668 - Exposure of Resource to Wrong SphereThe product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.