SB2023120515 - Improper authentication in Samsung Find My Mobile
Published: December 5, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Authentication (CVE-ID: CVE-2023-42571)
The vulnerability allows an attacker to unlock the device.
The vulnerability exists due to an error in the remote device unlock. An attacker with physical access to device can unlock the device remotely by resetting the Samsung Account password with SMS verification.
Remediation
Install update from vendor's website.