ID

VAR-202208-0609


CVE

CVE-2022-36832


TITLE

Samsung's  Cameralyzer  Vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2022-014237

DESCRIPTION

Improper access control vulnerability in WebApp in Cameralyzer prior to versions 3.2.22, 3.3.22, 3.4.22 and 3.5.51 allows attackers to access external storage as Cameralyzer privilege. Samsung's Cameralyzer Exists in unspecified vulnerabilities.Information may be obtained

Trust: 1.8

sources: NVD: CVE-2022-36832 // JVNDB: JVNDB-2022-014237 // VULHUB: VHN-432785 // VULMON: CVE-2022-36832

AFFECTED PRODUCTS

vendor:samsungmodel:cameralyzerscope:ltversion:3.4.22

Trust: 1.0

vendor:samsungmodel:cameralyzerscope:gteversion:3.5.0

Trust: 1.0

vendor:samsungmodel:cameralyzerscope:gteversion:3.4.0

Trust: 1.0

vendor:samsungmodel:cameralyzerscope:ltversion:3.3.22

Trust: 1.0

vendor:samsungmodel:cameralyzerscope:ltversion:3.2.22

Trust: 1.0

vendor:samsungmodel:cameralyzerscope:ltversion:3.5.51

Trust: 1.0

vendor:samsungmodel:cameralyzerscope:gteversion:3.3.0

Trust: 1.0

vendor:サムスンmodel:cameralyzerscope:eqversion: -

Trust: 0.8

vendor:サムスンmodel:cameralyzerscope:eqversion:3.4.0 that's all 3.4.22

Trust: 0.8

vendor:サムスンmodel:cameralyzerscope:eqversion:3.3.0 that's all 3.3.22

Trust: 0.8

vendor:サムスンmodel:cameralyzerscope:eqversion:3.2.22

Trust: 0.8

vendor:サムスンmodel:cameralyzerscope: - version: -

Trust: 0.8

vendor:サムスンmodel:cameralyzerscope:eqversion:3.5.0 that's all 3.5.51

Trust: 0.8

sources: JVNDB: JVNDB-2022-014237 // NVD: CVE-2022-36832

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2022-36832
value: LOW

Trust: 1.0

mobile.security@samsung.com: CVE-2022-36832
value: MEDIUM

Trust: 1.0

NVD: CVE-2022-36832
value: LOW

Trust: 0.8

CNNVD: CNNVD-202208-2298
value: LOW

Trust: 0.6

nvd@nist.gov: CVE-2022-36832
baseSeverity: LOW
baseScore: 3.3
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 1.8
impactScore: 1.4
version: 3.1

Trust: 1.0

mobile.security@samsung.com: CVE-2022-36832
baseSeverity: MEDIUM
baseScore: 4.0
vectorString: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 2.5
impactScore: 1.4
version: 3.1

Trust: 1.0

NVD: CVE-2022-36832
baseSeverity: LOW
baseScore: 3.3
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2022-014237 // CNNVD: CNNVD-202208-2298 // NVD: CVE-2022-36832 // NVD: CVE-2022-36832

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

problemtype:CWE-284

Trust: 1.0

problemtype:others (CWE-Other) [NVD evaluation ]

Trust: 0.8

problemtype:CWE-269

Trust: 0.1

sources: VULHUB: VHN-432785 // JVNDB: JVNDB-2022-014237 // NVD: CVE-2022-36832

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202208-2298

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202208-2298

PATCH

title:SAMSUNG Mobile devices Security vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=203908

Trust: 0.6

sources: CNNVD: CNNVD-202208-2298

EXTERNAL IDS

db:NVDid:CVE-2022-36832

Trust: 3.4

db:JVNDBid:JVNDB-2022-014237

Trust: 0.8

db:CNNVDid:CNNVD-202208-2298

Trust: 0.6

db:VULHUBid:VHN-432785

Trust: 0.1

db:VULMONid:CVE-2022-36832

Trust: 0.1

sources: VULHUB: VHN-432785 // VULMON: CVE-2022-36832 // JVNDB: JVNDB-2022-014237 // CNNVD: CNNVD-202208-2298 // NVD: CVE-2022-36832

REFERENCES

url:https://security.samsungmobile.com/serviceweb.smsb?year=2022&month=08

Trust: 2.4

url:https://nvd.nist.gov/vuln/detail/cve-2022-36832

Trust: 0.8

url:https://security.samsungmobile.com/serviceweb.smsb?year==2022&month=08

Trust: 0.7

url:https://cxsecurity.com/cveshow/cve-2022-36832/

Trust: 0.6

url:https://security.samsungmobile.com/serviceweb.smsb?year=2022&month=08

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-432785 // VULMON: CVE-2022-36832 // JVNDB: JVNDB-2022-014237 // CNNVD: CNNVD-202208-2298 // NVD: CVE-2022-36832

SOURCES

db:VULHUBid:VHN-432785
db:VULMONid:CVE-2022-36832
db:JVNDBid:JVNDB-2022-014237
db:CNNVDid:CNNVD-202208-2298
db:NVDid:CVE-2022-36832

LAST UPDATE DATE

2024-08-14T14:24:38.070000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-432785date:2022-10-27T00:00:00
db:VULMONid:CVE-2022-36832date:2022-08-06T00:00:00
db:JVNDBid:JVNDB-2022-014237date:2023-09-15T08:07:00
db:CNNVDid:CNNVD-202208-2298date:2023-06-28T00:00:00
db:NVDid:CVE-2022-36832date:2023-06-27T18:02:04.343

SOURCES RELEASE DATE

db:VULHUBid:VHN-432785date:2022-08-05T00:00:00
db:VULMONid:CVE-2022-36832date:2022-08-05T00:00:00
db:JVNDBid:JVNDB-2022-014237date:2023-09-15T00:00:00
db:CNNVDid:CNNVD-202208-2298date:2022-08-05T00:00:00
db:NVDid:CVE-2022-36832date:2022-08-05T16:15:14.937