CVE-2022-23998
Last modified
CVE-2022-23998 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. Improper access control vulnerability in Camera prior to versions 11.1.02.16 in Android R(11), 10.5.03.77 in Android Q(10) and 9.0.6.68 in Android P(9) allows untrusted applications to take a picture in screenlock status.. EPSS estimates a 0.58% chance of exploitation in the next 30 days.
Description
Improper access control vulnerability in Camera prior to versions 11.1.02.16 in Android R(11), 10.5.03.77 in Android Q(10) and 9.0.6.68 in Android P(9) allows untrusted applications to take a picture in screenlock status.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Samsung | Camera | < 11.1.02.16 |
| Samsung | Camera | < 10.5.03.77 |
| Samsung | Camera | < 9.0.6.68 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-23998?
How severe is CVE-2022-23998?
How do I fix CVE-2022-23998?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-23992XCOM Data Transport for Windows, Linux, and UNIX 11.6 releas…9.8
- CVE-2022-23993/usr/local/www/pkg.php in pfSense CE before 2.6.0 and pfSens…6.1
- CVE-2022-23994An Improper access control vulnerability in StBedtimeModeRec…3.3
- CVE-2022-23995Unprotected component vulnerability in StBedtimeModeAlarmRec…3.3
- CVE-2022-23996Unprotected component vulnerability in StTheaterModeReceiver…3.3
- CVE-2022-23997Unprotected component vulnerability in StTheaterModeDuration…3.3
- CVE-2022-23999PendingIntent hijacking vulnerability in CpaReceiver prior t…3.3
- CVE-2022-2400External Control of File Name or Path in GitHub repository d…5.3
- CVE-2022-24000PendingIntent hijacking vulnerability in DataUsageReminderRe…3.3
- CVE-2022-24001Information disclosure vulnerability in Edge Panel prior to …4.6
- CVE-2022-24002Improper Authorization vulnerability in Link Sharing prior t…5.3
- CVE-2022-24003Exposure of Sensitive Information vulnerability in Bixby Vis…5.3
Are you affected by CVE-2022-23998?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
