Skip to main content

Vendor/product archive

samsung / smartthings CVEs

Beta · best-effort

20 CVEs tagged to samsung / smartthings0 Critical, 2 High, 15 Medium, 3 Low, 0 Unrated.

CVE-2025-2233

Published Mar 11, 2025

Samsung SmartThings Improper Verification of Cryptographic Signature Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentica…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-49416

Published Dec 3, 2024

Use of implicit intent for sensitive communication in SmartThings prior to version 1.8.21 allows local attackers to get sensitive information.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34596

Published Jul 2, 2024

Improper authentication in SmartThings prior to version 1.8.17 allows remote attackers to bypass the expiration date for members set by the owner.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-20852

Published Apr 2, 2024

Improper verification of intent by broadcast receiver vulnerability in SmartThings prior to version 1.8.13.22 allows local attackers to access testing configuration.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39871

Published Oct 7, 2022

Improper access control vulnerability cloudNotificationManager.java in SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcas…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39870

Published Oct 7, 2022

Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via PUSH_MESSAGE_RECE…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39869

Published Oct 7, 2022

Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via REMOVE_PERSISTENT…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39868

Published Oct 7, 2022

Improper access control vulnerability in GedSamsungAccount.kt SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39867

Published Oct 7, 2022

Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via SHOW_PERSISTENT_B…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39866

Published Oct 7, 2022

Improper access control vulnerability in RegisteredEventMediator.kt SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39865

Published Oct 7, 2022

Improper access control vulnerability in ContentsSharingActivity.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39864

Published Oct 7, 2022

Improper access control vulnerability in WifiSetupLaunchHelper in SmartThings prior to version 1.7.89.25 allows attackers to access sensitive information via implicit intent.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-30749

Published Jun 7, 2022

Improper access control vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to add arbitrary smart devices by bypassing login activity.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-30747

Published Jun 7, 2022

PendingIntent hijacking vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to access files without permission via implicit Intent.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30746

Published Jun 7, 2022

Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely using javascript interface API.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25508

Published Nov 5, 2021

Improper privilege management vulnerability in API Key used in SmartThings prior to 1.7.73.22 allows an attacker to abuse the API key without limitation.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25378

Published Apr 9, 2021

Improper access control of certain port in SmartThings prior to version 1.7.63.6 allows remote temporary denial of service.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-20 of 20 CVEsPage 1 of 1