Samsung
4,624 known vulnerabilities
Top Products
Improper access control vulnerability in NfcTile prior to SMR Jan-2023 Release 1 allows to attacker to use NFC without u
Hardcoded AES key to encrypt cardemulation PINs in NFC prior to SMR Jan-2023 Release 1 allows attackers to access cardem
Improper access control vulnerability in telecom application prior to SMR JAN-2023 Release 1 allows local attackers to g
Improper Handling of Insufficient Permissions or Privileges vulnerability in SemChameleonHelper prior to SMR Jan-2023 Re
Improper authorization vulnerability in ChnFileShareKit prior to SMR Jan-2023 Release 1 allows attacker to control BLE a
Improper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attacke
Improper Handling of Insufficient Permissions or Privileges vulnerability in KnoxCustomManagerService prior to SMR Jan-2
Use of Externally-Controlled Format String vulnerabilities in STST TA prior to SMR Jan-2023 Release 1 allows arbitrary c
The Samsung TV (2021 and 2022 model) smart remote control allows attackers to enable microphone access via Bluetooth spo
Improper access control vulnerability in Calendar prior to versions 11.6.08.0 in Android Q(10), 12.2.11.3000 in Android
Improper check or handling of exceptional conditions vulnerability in Samsung Pass prior to version 4.0.06.1 allows atta
Improper access control vulnerability in Samsung Pass prior to version 4.0.06.7 allow physical attackers to access data
Insufficient verification of data authenticity vulnerability in Samsung Gear IconX PC Manager prior to version 2.1.22101
Improper authorization in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to get sensitive inform
Improper authentication in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to disable the network
Sensitive information exposure vulnerability in FmmBaseModel in Galaxy Buds Pro Manage prior to version 4.1.22092751 all
Improper access control in Samsung Pass prior to version 4.0.05.1 allows attackers to unauthenticated access via keep op
Heap overflow vulnerability in parse_pce function in libsavsaudio.so in Editor Lite prior to version 4.0.41.3 allows att
Improper Authorization in Samsung Billing prior to version 5.0.56.0 allows attacker to get sensitive information.
Improper access control vulnerability in GalaxyWatch4Plugin prior to versions 2.2.11.22101351 and 2.2.12.22101351 allows
Improper input validation vulnerability for processing SIB12 PDU in Exynos modems prior to SMR Sep-2022 Release allows r
Improper access control vulnerability in Samsung Checkout prior to version 5.0.55.3 allows attackers to access sensitive
Improper access control vulnerability in ProfileSharingAccount in Group Sharing prior to versions 13.0.6.15 in Android S
Insertion of Sensitive Information into Log in PushRegIdUpdateClient of SReminder prior to 8.2.01.13 allows attacker to
Improper component protection vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthorized
Sensitive log information leakage vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthori
Improper authorization vulnerability in Samsung Internet prior to version 18.0.4.14 allows physical attackers to add boo
Improper restriction of broadcasting Intent in ShareLive prior to version 13.2.03.5 leaks MAC address of the connected B
Improper access control vulnerability cloudNotificationManager.java in SmartThings prior to version 1.7.89.0 allows atta
Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows atta
Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows atta
Improper access control vulnerability in GedSamsungAccount.kt SmartThings prior to version 1.7.89.0 allows attackers to
Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows atta
Improper access control vulnerability in RegisteredEventMediator.kt SmartThings prior to version 1.7.89.0 allows attacke
Improper access control vulnerability in ContentsSharingActivity.java SmartThings prior to version 1.7.89.0 allows attac
Improper access control vulnerability in WifiSetupLaunchHelper in SmartThings prior to version 1.7.89.25 allows attacker
Intent redirection vulnerability in Samsung Account prior to version 13.5.01.3 allows attackers to access content provid
Improper authorization in Dynamic Lockscreen prior to SMR Sep-2022 Release 1 in Android R(11) and 3.3.03.66 in Android S
Unprotected Receiver in AtBroadcastReceiver in FactoryCamera prior to version 3.5.51 allows attackers to record video wi
Improper access control vulnerability in QuickShare prior to version 13.2.3.5 allows attackers to access sensitive infor
Implicit intent hijacking vulnerability in UPHelper library prior to version 3.0.12 allows attackers to access sensitive
Path traversal vulnerability in AtBroadcastReceiver in FactoryCamera prior to version 3.5.51 allows attackers to write a
Improper access control vulnerability in CameraTestActivity in FactoryCameraFB prior to version 3.5.51 allows attackers
Improper protection in IOMMU prior to SMR Oct-2022 Release 1 allows unauthorized access to secure memory.
An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). l2_packet_receive_timeout in wpa_supplicant/sr
An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). createDB in security/provisioning/src/provisio
A Memory Allocation with Excessive Size Value vulnerablity in the TEE_Realloc function in Samsung mTower through 0.3.0 a
The function tee_obj_free in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (D
A Buffer Access with Incorrect Length Value vulnerablity in the TEE_MACUpdate function in Samsung mTower through 0.3.0 a
A NULL pointer dereference issue in the TEE_MACCompareFinal function in Samsung mTower through 0.3.0 allows a trusted ap
Frequently Asked Questions
How many CVEs affect Samsung?
Samsung has 4,624 CVE records in our database, including 376 critical and 1561 high severity vulnerabilities. 15 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Samsung vulnerabilities?
Samsung has 376 critical severity (CVSS 9.0+) and 1561 high severity (CVSS 7.0-8.9) vulnerabilities. 15 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Samsung vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Samsung products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Samsung Vulnerabilities
CyberStrike scans your infrastructure for Samsung vulnerabilities and provides real-time remediation guidance.
Get Started