ID

VAR-202402-1489


CVE

CVE-2024-20824


TITLE

Samsung's  Galaxy Store  Vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2024-002419

DESCRIPTION

Implicit intent hijacking vulnerability in VoiceSearch of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent. Samsung's Galaxy Store Exists in unspecified vulnerabilities.Information may be obtained

Trust: 1.62

sources: NVD: CVE-2024-20824 // JVNDB: JVNDB-2024-002419

AFFECTED PRODUCTS

vendor:samsungmodel:galaxy storescope:ltversion:4.5.63.6

Trust: 1.0

vendor:サムスンmodel:galaxy storescope: - version: -

Trust: 0.8

vendor:サムスンmodel:galaxy storescope:eqversion: -

Trust: 0.8

vendor:サムスンmodel:galaxy storescope:eqversion:4.5.63.6

Trust: 0.8

sources: JVNDB: JVNDB-2024-002419 // NVD: CVE-2024-20824

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2024-20824
value: MEDIUM

Trust: 1.0

mobile.security@samsung.com: CVE-2024-20824
value: MEDIUM

Trust: 1.0

NVD: CVE-2024-20824
value: MEDIUM

Trust: 0.8

nvd@nist.gov: CVE-2024-20824
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 1.8
impactScore: 3.6
version: 3.1

Trust: 2.0

NVD: CVE-2024-20824
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2024-002419 // NVD: CVE-2024-20824 // NVD: CVE-2024-20824

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:Lack of information (CWE-noinfo) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2024-002419 // NVD: CVE-2024-20824

EXTERNAL IDS

db:NVDid:CVE-2024-20824

Trust: 2.6

db:JVNDBid:JVNDB-2024-002419

Trust: 0.8

sources: JVNDB: JVNDB-2024-002419 // NVD: CVE-2024-20824

REFERENCES

url:https://security.samsungmobile.com/serviceweb.smsb?year=2024&month=02

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2024-20824

Trust: 0.8

sources: JVNDB: JVNDB-2024-002419 // NVD: CVE-2024-20824

SOURCES

db:JVNDBid:JVNDB-2024-002419
db:NVDid:CVE-2024-20824

LAST UPDATE DATE

2024-08-14T14:42:47.128000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2024-002419date:2024-02-14T05:45:00
db:NVDid:CVE-2024-20824date:2024-02-09T17:31:03.593

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2024-002419date:2024-02-14T00:00:00
db:NVDid:CVE-2024-20824date:2024-02-06T03:15:10.240