← back
CVE-2022-36872

CVE-2022-36872

CVSS 5 MEDIUMEPSS 0.2%CWE-285
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
09 Sep 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Pending Intent hijacking vulnerability in SpayNotification in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:L

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →