CVE-2024-20805

EUVD-2024-18520
Path traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers to write arbitrary file.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.3 LOW
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
SamsungMobileCNA
3.3 LOW
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 21%
Affected Products (NVD)
VendorProductVersion
samsungandroid
11.0
samsungandroid
11.0:smr-apr-2021-r1
samsungandroid
11.0:smr-apr-2022-r1
samsungandroid
11.0:smr-apr-2023-r1
samsungandroid
11.0:smr-aug-2021-r1
samsungandroid
11.0:smr-aug-2022-r1
samsungandroid
11.0:smr-aug-2023-r1
samsungandroid
11.0:smr-dec-2020-r1
samsungandroid
11.0:smr-dec-2021-r1
samsungandroid
11.0:smr-dec-2022-r1
samsungandroid
11.0:smr-dec-2023-r1
samsungandroid
11.0:smr-feb-2021-r1
samsungandroid
11.0:smr-feb-2022-r1
samsungandroid
11.0:smr-feb-2023-r1
samsungandroid
11.0:smr-jan-2021-r1
samsungandroid
11.0:smr-jan-2022-r1
samsungandroid
11.0:smr-jan-2023-r1
samsungandroid
11.0:smr-jul-2021-r1
samsungandroid
11.0:smr-jul-2022-r1
samsungandroid
11.0:smr-jul-2023-r1
samsungandroid
11.0:smr-jun-2021-r1
samsungandroid
11.0:smr-jun-2022-r1
samsungandroid
11.0:smr-jun-2023-r1
samsungandroid
11.0:smr-mar-2021-r1
samsungandroid
11.0:smr-mar-2022-r1
samsungandroid
11.0:smr-mar-2023-r1
samsungandroid
11.0:smr-may-2021-r1
samsungandroid
11.0:smr-may-2022-r1
samsungandroid
11.0:smr-may-2023-r1
samsungandroid
11.0:smr-nov-2021-r1
samsungandroid
11.0:smr-nov-2022-r1
samsungandroid
11.0:smr-nov-2023-r1
samsungandroid
11.0:smr-oct-2021-r1
samsungandroid
11.0:smr-oct-2022-r1
samsungandroid
11.0:smr-oct-2023-r1
samsungandroid
11.0:smr-sep-2021-r1
samsungandroid
11.0:smr-sep-2022-r1
samsungandroid
11.0:smr-sep-2023-r1
samsungandroid
12.0
samsungandroid
12.0:smr-apr-2022-r1
samsungandroid
12.0:smr-apr-2023-r1
samsungandroid
12.0:smr-aug-2022-r1
samsungandroid
12.0:smr-aug-2023-r1
samsungandroid
12.0:smr-dec-2021-r1
samsungandroid
12.0:smr-dec-2022-r1
samsungandroid
12.0:smr-dec-2023-r1
samsungandroid
12.0:smr-feb-2022-r1
samsungandroid
12.0:smr-feb-2023-r1
samsungandroid
12.0:smr-jan-2022-r1
samsungandroid
12.0:smr-jan-2023-r1
samsungandroid
12.0:smr-jul-2022-r1
samsungandroid
12.0:smr-jul-2023-r1
samsungandroid
12.0:smr-jun-2022-r1
samsungandroid
12.0:smr-jun-2023-r1
samsungandroid
12.0:smr-mar-2022-r1
samsungandroid
12.0:smr-mar-2023-r1
samsungandroid
12.0:smr-may-2022-r1
samsungandroid
12.0:smr-may-2023-r1
samsungandroid
12.0:smr-nov-2021-r1
samsungandroid
12.0:smr-nov-2022-r1
samsungandroid
12.0:smr-nov-2023-r1
samsungandroid
12.0:smr-oct-2022-r1
samsungandroid
12.0:smr-oct-2023-r1
samsungandroid
12.0:smr-sep-2022-r1
samsungandroid
12.0:smr-sep-2023-r1
samsungmyfiles
𝑥
< 14.5.00.21
𝑥
= Vulnerable software versions