7.5
CVSSv3

CVE-2022-39870

Published: 07/10/2022 Updated: 11/10/2022
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows malicious users to access sensitive information via PUSH_MESSAGE_RECEIVED broadcast.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

samsung smartthings