Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
samsung smartthings vulnerabilities and exploits
(subscribe to this query)
409
VMScore
CVE-2022-30749
Improper access control vulnerability in Smart Things before 1.7.85.25 allows local malicious users to add arbitrary smart devices by bypassing login activity.
Samsung Smartthings
NA
CVE-2022-39866
Improper access control vulnerability in RegisteredEventMediator.kt SmartThings prior to version 1.7.89.0 allows malicious users to access sensitive information via implicit broadcast.
Samsung Smartthings
668
VMScore
CVE-2021-25508
Improper privilege management vulnerability in API Key used in SmartThings before 1.7.73.22 allows an malicious user to abuse the API key without limitation.
Samsung Smartthings
445
VMScore
CVE-2022-30746
Missing caller check in Smart Things prior to version 1.7.85.12 allows malicious user to access senstive information remotely using javascript interface API.
Samsung Smartthings
187
VMScore
CVE-2022-30747
PendingIntent hijacking vulnerability in Smart Things before 1.7.85.25 allows local malicious users to access files without permission via implicit Intent.
Samsung Smartthings
NA
CVE-2022-39868
Improper access control vulnerability in GedSamsungAccount.kt SmartThings prior to version 1.7.89.0 allows malicious users to access sensitive information via implicit broadcast.
Samsung Smartthings
NA
CVE-2022-39870
Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows malicious users to access sensitive information via PUSH_MESSAGE_RECEIVED broadcast.
Samsung Smartthings
NA
CVE-2022-39864
Improper access control vulnerability in WifiSetupLaunchHelper in SmartThings prior to version 1.7.89.25 allows malicious users to access sensitive information via implicit intent.
Samsung Smartthings
NA
CVE-2022-39865
Improper access control vulnerability in ContentsSharingActivity.java SmartThings prior to version 1.7.89.0 allows malicious users to access sensitive information via implicit broadcast.
Samsung Smartthings
NA
CVE-2022-39867
Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows malicious users to access sensitive information via SHOW_PERSISTENT_BANNER broadcast.
Samsung Smartthings
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3080
log injection
CVE-2024-6041
CVE-2024-37661
XML external entity
CVE-2024-0845
privilege escalation
CVE-2023-37057
CVE-2024-27801
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »