CVE Vulnerabilities

CVE-2023-30713

Improper Privilege Management

Published: Sep 06, 2023 | Modified: Nov 07, 2023
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Improper privilege management vulnerability in FolderLockNotifier in One UI Home prior to SMR Sep-2023 Release 1 allows local attackers to change some settings of the folder lock.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Android Samsung 11.0 (including) 11.0 (including)
Android Samsung 11.0-smr-apr-2021-r1 (including) 11.0-smr-apr-2021-r1 (including)
Android Samsung 11.0-smr-apr-2022-r1 (including) 11.0-smr-apr-2022-r1 (including)
Android Samsung 11.0-smr-apr-2023-r1 (including) 11.0-smr-apr-2023-r1 (including)
Android Samsung 11.0-smr-aug-2021-r1 (including) 11.0-smr-aug-2021-r1 (including)
Android Samsung 11.0-smr-aug-2022-r1 (including) 11.0-smr-aug-2022-r1 (including)
Android Samsung 11.0-smr-aug-2023-r1 (including) 11.0-smr-aug-2023-r1 (including)
Android Samsung 11.0-smr-dec-2020-r1 (including) 11.0-smr-dec-2020-r1 (including)
Android Samsung 11.0-smr-dec-2021-r1 (including) 11.0-smr-dec-2021-r1 (including)
Android Samsung 11.0-smr-dec-2022-r1 (including) 11.0-smr-dec-2022-r1 (including)
Android Samsung 11.0-smr-feb-2021-r1 (including) 11.0-smr-feb-2021-r1 (including)
Android Samsung 11.0-smr-feb-2022-r1 (including) 11.0-smr-feb-2022-r1 (including)
Android Samsung 11.0-smr-feb-2023-r1 (including) 11.0-smr-feb-2023-r1 (including)
Android Samsung 11.0-smr-jan-2021-r1 (including) 11.0-smr-jan-2021-r1 (including)
Android Samsung 11.0-smr-jan-2022-r1 (including) 11.0-smr-jan-2022-r1 (including)
Android Samsung 11.0-smr-jan-2023-r1 (including) 11.0-smr-jan-2023-r1 (including)
Android Samsung 11.0-smr-jul-2021-r1 (including) 11.0-smr-jul-2021-r1 (including)
Android Samsung 11.0-smr-jul-2022-r1 (including) 11.0-smr-jul-2022-r1 (including)
Android Samsung 11.0-smr-jul-2023-r1 (including) 11.0-smr-jul-2023-r1 (including)
Android Samsung 11.0-smr-jun-2021-r1 (including) 11.0-smr-jun-2021-r1 (including)
Android Samsung 11.0-smr-jun-2022-r1 (including) 11.0-smr-jun-2022-r1 (including)
Android Samsung 11.0-smr-jun-2023-r1 (including) 11.0-smr-jun-2023-r1 (including)
Android Samsung 11.0-smr-mar-2021-r1 (including) 11.0-smr-mar-2021-r1 (including)
Android Samsung 11.0-smr-mar-2022-r1 (including) 11.0-smr-mar-2022-r1 (including)
Android Samsung 11.0-smr-mar-2023-r1 (including) 11.0-smr-mar-2023-r1 (including)
Android Samsung 11.0-smr-may-2021-r1 (including) 11.0-smr-may-2021-r1 (including)
Android Samsung 11.0-smr-may-2022-r1 (including) 11.0-smr-may-2022-r1 (including)
Android Samsung 11.0-smr-may-2023-r1 (including) 11.0-smr-may-2023-r1 (including)
Android Samsung 11.0-smr-nov-2021-r1 (including) 11.0-smr-nov-2021-r1 (including)
Android Samsung 11.0-smr-nov-2022-r1 (including) 11.0-smr-nov-2022-r1 (including)
Android Samsung 11.0-smr-oct-2021-r1 (including) 11.0-smr-oct-2021-r1 (including)
Android Samsung 11.0-smr-oct-2022-r1 (including) 11.0-smr-oct-2022-r1 (including)
Android Samsung 11.0-smr-sep-2021-r1 (including) 11.0-smr-sep-2021-r1 (including)
Android Samsung 11.0-smr-sep-2022-r1 (including) 11.0-smr-sep-2022-r1 (including)
Android Samsung 12.0 (including) 12.0 (including)
Android Samsung 12.0-smr-apr-2022-r1 (including) 12.0-smr-apr-2022-r1 (including)
Android Samsung 12.0-smr-apr-2023-r1 (including) 12.0-smr-apr-2023-r1 (including)
Android Samsung 12.0-smr-aug-2022-r1 (including) 12.0-smr-aug-2022-r1 (including)
Android Samsung 12.0-smr-aug-2023-r1 (including) 12.0-smr-aug-2023-r1 (including)
Android Samsung 12.0-smr-dec-2021-r1 (including) 12.0-smr-dec-2021-r1 (including)
Android Samsung 12.0-smr-dec-2022-r1 (including) 12.0-smr-dec-2022-r1 (including)
Android Samsung 12.0-smr-feb-2022-r1 (including) 12.0-smr-feb-2022-r1 (including)
Android Samsung 12.0-smr-feb-2023-r1 (including) 12.0-smr-feb-2023-r1 (including)
Android Samsung 12.0-smr-jan-2022-r1 (including) 12.0-smr-jan-2022-r1 (including)
Android Samsung 12.0-smr-jan-2023-r1 (including) 12.0-smr-jan-2023-r1 (including)
Android Samsung 12.0-smr-jul-2022-r1 (including) 12.0-smr-jul-2022-r1 (including)
Android Samsung 12.0-smr-jul-2023-r1 (including) 12.0-smr-jul-2023-r1 (including)
Android Samsung 12.0-smr-jun-2022-r1 (including) 12.0-smr-jun-2022-r1 (including)
Android Samsung 12.0-smr-jun-2023-r1 (including) 12.0-smr-jun-2023-r1 (including)
Android Samsung 12.0-smr-mar-2022-r1 (including) 12.0-smr-mar-2022-r1 (including)
Android Samsung 12.0-smr-mar-2023-r1 (including) 12.0-smr-mar-2023-r1 (including)
Android Samsung 12.0-smr-may-2022-r1 (including) 12.0-smr-may-2022-r1 (including)
Android Samsung 12.0-smr-may-2023-r1 (including) 12.0-smr-may-2023-r1 (including)
Android Samsung 12.0-smr-nov-2021-r1 (including) 12.0-smr-nov-2021-r1 (including)
Android Samsung 12.0-smr-nov-2022-r1 (including) 12.0-smr-nov-2022-r1 (including)
Android Samsung 12.0-smr-oct-2022-r1 (including) 12.0-smr-oct-2022-r1 (including)
Android Samsung 12.0-smr-sep-2022-r1 (including) 12.0-smr-sep-2022-r1 (including)
Android Samsung 13.0 (including) 13.0 (including)
Android Samsung 13.0-smr-apr-2023-r1 (including) 13.0-smr-apr-2023-r1 (including)
Android Samsung 13.0-smr-aug-2023-r1 (including) 13.0-smr-aug-2023-r1 (including)
Android Samsung 13.0-smr-dec-2022-r1 (including) 13.0-smr-dec-2022-r1 (including)
Android Samsung 13.0-smr-feb-2023-r1 (including) 13.0-smr-feb-2023-r1 (including)
Android Samsung 13.0-smr-jan-2023-r1 (including) 13.0-smr-jan-2023-r1 (including)
Android Samsung 13.0-smr-jul-2023-r1 (including) 13.0-smr-jul-2023-r1 (including)
Android Samsung 13.0-smr-jun-2023-r1 (including) 13.0-smr-jun-2023-r1 (including)
Android Samsung 13.0-smr-mar-2023-r1 (including) 13.0-smr-mar-2023-r1 (including)
Android Samsung 13.0-smr-may-2023-r1 (including) 13.0-smr-may-2023-r1 (including)
Android Samsung 13.0-smr-nov-2022-r1 (including) 13.0-smr-nov-2022-r1 (including)
Android Samsung 13.0-smr-oct-2022-r1 (including) 13.0-smr-oct-2022-r1 (including)

Potential Mitigations

References