ID

VAR-202402-0736


CVE

CVE-2024-20827


TITLE

Samsung's  Gallery  Vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2024-002499

DESCRIPTION

Improper access control vulnerability in Samsung Gallery prior to version 14.5.04.4 allows physical attackers to access the picture using physical keyboard on the lockscreen. Samsung's Gallery Exists in unspecified vulnerabilities.Information may be obtained

Trust: 1.71

sources: NVD: CVE-2024-20827 // JVNDB: JVNDB-2024-002499 // VULMON: CVE-2024-20827

AFFECTED PRODUCTS

vendor:samsungmodel:galleryscope:ltversion:14.5.04.4

Trust: 1.0

vendor:サムスンmodel:galleryscope:eqversion: -

Trust: 0.8

vendor:サムスンmodel:galleryscope:eqversion:14.5.04.4

Trust: 0.8

vendor:サムスンmodel:galleryscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2024-002499 // NVD: CVE-2024-20827

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2024-20827
value: MEDIUM

Trust: 1.0

mobile.security@samsung.com: CVE-2024-20827
value: MEDIUM

Trust: 1.0

NVD: CVE-2024-20827
value: MEDIUM

Trust: 0.8

nvd@nist.gov: CVE-2024-20827
baseSeverity: MEDIUM
baseScore: 4.6
vectorString: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: PHYSICAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 0.9
impactScore: 3.6
version: 3.1

Trust: 2.0

NVD: CVE-2024-20827
baseSeverity: MEDIUM
baseScore: 4.6
vectorString: CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: PHYSICAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2024-002499 // NVD: CVE-2024-20827 // NVD: CVE-2024-20827

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

problemtype:others (CWE-Other) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2024-002499 // NVD: CVE-2024-20827

EXTERNAL IDS

db:NVDid:CVE-2024-20827

Trust: 2.7

db:JVNDBid:JVNDB-2024-002499

Trust: 0.8

db:VULMONid:CVE-2024-20827

Trust: 0.1

sources: VULMON: CVE-2024-20827 // JVNDB: JVNDB-2024-002499 // NVD: CVE-2024-20827

REFERENCES

url:https://security.samsungmobile.com/serviceweb.smsb?year=2024&month=02

Trust: 1.9

url:https://nvd.nist.gov/vuln/detail/cve-2024-20827

Trust: 0.8

url:https://nvd.nist.gov

Trust: 0.1

sources: VULMON: CVE-2024-20827 // JVNDB: JVNDB-2024-002499 // NVD: CVE-2024-20827

SOURCES

db:VULMONid:CVE-2024-20827
db:JVNDBid:JVNDB-2024-002499
db:NVDid:CVE-2024-20827

LAST UPDATE DATE

2024-08-14T15:31:38.342000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2024-20827date:2024-02-06T00:00:00
db:JVNDBid:JVNDB-2024-002499date:2024-02-15T00:56:00
db:NVDid:CVE-2024-20827date:2024-02-13T21:01:49.557

SOURCES RELEASE DATE

db:VULMONid:CVE-2024-20827date:2024-02-06T00:00:00
db:JVNDBid:JVNDB-2024-002499date:2024-02-15T00:00:00
db:NVDid:CVE-2024-20827date:2024-02-06T03:15:10.813