CVE Vulnerabilities

CVE-2022-33707

Small Space of Random Values

Published: Jul 12, 2022 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Improper identifier creation logic in Find My Mobile prior to version 7.2.24.12 allows attacker to identify the device.

Weakness

The number of possible random values is smaller than needed by the product, making it more susceptible to brute force attacks.

Affected Software

Name Vendor Start Version End Version
Find_my_mobile Samsung * 7.2.24.12 (excluding)

Potential Mitigations

References