SB2023120515 - Improper authentication in Samsung Find My Mobile



SB2023120515 - Improper authentication in Samsung Find My Mobile

Published: December 5, 2023

Security Bulletin ID SB2023120515
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Physical access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Authentication (CVE-ID: CVE-2023-42571)

The vulnerability allows an attacker to unlock the device.

The vulnerability exists due to an error in the remote device unlock. An attacker with physical access to device can unlock the device remotely by resetting the Samsung Account password with SMS verification.


Remediation

Install update from vendor's website.