Fiche vulnérabilité
CVE-2022-30749 : faille élevée samsung smartthings (CVSS 7.8)
Description
Improper access control vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to add arbitrary smart devices by bypassing login activity.
En bref
- Sévérité
- Élevée (CVSS 7.8)
- Vecteur CVSS
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 7 juin 2022
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- samsung smartthings