CVE Vulnerabilities

CVE-2023-21484

Improper Authentication

Published: May 04, 2023 | Modified: May 10, 2023
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Improper access control vulnerability in AppLock prior to SMR May-2023 Release 1 allows local attackers without proper permission to execute a privileged operation.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Android Samsung 11.0 11.0
Android Samsung 11.0 11.0
Android Samsung 11.0 11.0
Android Samsung 11.0 11.0
Android Samsung 11.0 11.0
Android Samsung 11.0 11.0
Android Samsung 11.0 11.0
Android Samsung 11.0 11.0
Android Samsung 11.0 11.0
Android Samsung 11.0 11.0
Android Samsung 11.0 11.0
Android Samsung 11.0 11.0
Android Samsung 11.0 11.0
Android Samsung 11.0 11.0
Android Samsung 11.0 11.0
Android Samsung 11.0 11.0
Android Samsung 11.0 11.0
Android Samsung 11.0 11.0
Android Samsung 11.0 11.0
Android Samsung 11.0 11.0
Android Samsung 11.0 11.0
Android Samsung 11.0 11.0
Android Samsung 11.0 11.0
Android Samsung 11.0 11.0
Android Samsung 11.0 11.0
Android Samsung 11.0 11.0
Android Samsung 11.0 11.0
Android Samsung 12.0 12.0
Android Samsung 12.0 12.0
Android Samsung 12.0 12.0
Android Samsung 12.0 12.0
Android Samsung 12.0 12.0
Android Samsung 12.0 12.0
Android Samsung 12.0 12.0
Android Samsung 12.0 12.0
Android Samsung 12.0 12.0
Android Samsung 12.0 12.0
Android Samsung 12.0 12.0
Android Samsung 12.0 12.0
Android Samsung 12.0 12.0
Android Samsung 12.0 12.0
Android Samsung 12.0 12.0
Android Samsung 13.0 13.0
Android Samsung 13.0 13.0
Android Samsung 13.0 13.0
Android Samsung 13.0 13.0
Android Samsung 13.0 13.0
Android Samsung 13.0 13.0
Android Samsung 13.0 13.0
Android Samsung 12.0 12.0
Android Samsung 13.0 13.0

Potential Mitigations

References