ID

VAR-202207-0737


CVE

CVE-2022-33711


TITLE

Samsung's  Windows  for  android usb driver  Vulnerability related to insufficient data integrity verification in

Trust: 0.8

sources: JVNDB: JVNDB-2022-013218

DESCRIPTION

Improper validation of integrity check vulnerability in Samsung USB Driver Windows Installer for Mobile Phones prior to version 1.7.56.0 allows local attackers to delete arbitrary directory using directory junction. Samsung's Windows for android usb driver contains a vulnerability related to insufficient data integrity verification.Information may be tampered with. Samsung USB Driver Windows Installer for Mobile Phones is a driver used when Samsung (SAMSUNG) mobile devices are connected to PC. The vulnerability stems from incorrect validation logic in the program, and an attacker can exploit this vulnerability to delete any directory

Trust: 2.25

sources: NVD: CVE-2022-33711 // JVNDB: JVNDB-2022-013218 // CNVD: CNVD-2022-76490 // VULMON: CVE-2022-33711

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2022-76490

AFFECTED PRODUCTS

vendor:samsungmodel:android usb driverscope:ltversion:1.7.56.0

Trust: 1.0

vendor:サムスンmodel:android usb driverscope:eqversion: -

Trust: 0.8

vendor:サムスンmodel:android usb driverscope:eqversion:1.7.56.0

Trust: 0.8

vendor:サムスンmodel:android usb driverscope: - version: -

Trust: 0.8

vendor:samsungmodel:usb driver windows installerscope:ltversion:1.7.56.0

Trust: 0.6

sources: CNVD: CNVD-2022-76490 // JVNDB: JVNDB-2022-013218 // NVD: CVE-2022-33711

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2022-33711
value: MEDIUM

Trust: 1.0

NVD: CVE-2022-33711
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2022-76490
value: LOW

Trust: 0.6

CNNVD: CNNVD-202207-984
value: MEDIUM

Trust: 0.6

VULMON: CVE-2022-33711
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2022-33711
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:N/I:P/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

CNVD: CNVD-2022-76490
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:N/I:P/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2022-33711
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 1.8
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: CVE-2022-33711
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2022-76490 // VULMON: CVE-2022-33711 // JVNDB: JVNDB-2022-013218 // CNNVD: CNNVD-202207-984 // NVD: CVE-2022-33711

PROBLEMTYPE DATA

problemtype:CWE-354

Trust: 1.0

problemtype:Incomplete data integrity verification (CWE-354) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2022-013218 // NVD: CVE-2022-33711

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202207-984

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202207-984

PATCH

title:Patch for Samsung USB Driver Windows Installer for Mobile Phones Input Validation Error Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/356921

Trust: 0.6

title:SAMSUNG USB Driver Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=199911

Trust: 0.6

sources: CNVD: CNVD-2022-76490 // CNNVD: CNNVD-202207-984

EXTERNAL IDS

db:NVDid:CVE-2022-33711

Trust: 3.9

db:JVNDBid:JVNDB-2022-013218

Trust: 0.8

db:CNVDid:CNVD-2022-76490

Trust: 0.6

db:CNNVDid:CNNVD-202207-984

Trust: 0.6

db:VULMONid:CVE-2022-33711

Trust: 0.1

sources: CNVD: CNVD-2022-76490 // VULMON: CVE-2022-33711 // JVNDB: JVNDB-2022-013218 // CNNVD: CNNVD-202207-984 // NVD: CVE-2022-33711

REFERENCES

url:https://security.samsungmobile.com/serviceweb.smsb?year==2022&month=07

Trust: 2.5

url:https://nvd.nist.gov/vuln/detail/cve-2022-33711

Trust: 1.4

url:https://cxsecurity.com/cveshow/cve-2022-33711/

Trust: 1.2

url:https://cwe.mitre.org/data/definitions/354.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: CNVD: CNVD-2022-76490 // VULMON: CVE-2022-33711 // JVNDB: JVNDB-2022-013218 // CNNVD: CNNVD-202207-984 // NVD: CVE-2022-33711

SOURCES

db:CNVDid:CNVD-2022-76490
db:VULMONid:CVE-2022-33711
db:JVNDBid:JVNDB-2022-013218
db:CNNVDid:CNNVD-202207-984
db:NVDid:CVE-2022-33711

LAST UPDATE DATE

2024-08-14T14:37:27.082000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2022-76490date:2022-11-11T00:00:00
db:VULMONid:CVE-2022-33711date:2022-07-19T00:00:00
db:JVNDBid:JVNDB-2022-013218date:2023-09-06T08:22:00
db:CNNVDid:CNNVD-202207-984date:2022-07-20T00:00:00
db:NVDid:CVE-2022-33711date:2022-07-19T14:37:25.053

SOURCES RELEASE DATE

db:CNVDid:CNVD-2022-76490date:2022-10-17T00:00:00
db:VULMONid:CVE-2022-33711date:2022-07-12T00:00:00
db:JVNDBid:JVNDB-2022-013218date:2023-09-06T00:00:00
db:CNNVDid:CNNVD-202207-984date:2022-07-12T00:00:00
db:NVDid:CVE-2022-33711date:2022-07-12T14:15:18.450