ZeroHour

CVE-2022-30746

CVSS 3.1
7.5 high
EPSS
<1%p57
Published
()
Modified
Description

Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely using javascript interface API.

Vendors
samsung
Products
smartthings
Weakness
CWE-285, CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.