{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2023-42571","assignerOrgId":"3af57064-a867-422c-b2ad-40307b65c458","state":"PUBLISHED","assignerShortName":"SamsungMobile","dateReserved":"2023-09-11T23:55:08.356Z","datePublished":"2023-12-05T02:44:28.948Z","dateUpdated":"2024-12-02T17:12:01.956Z"},"containers":{"cna":{"problemTypes":[{"descriptions":[{"lang":"en","description":"CWE-287: Improper Authentication"}]}],"affected":[{"vendor":"Samsung Mobile","product":"Find My Mobile","versions":[{"status":"unaffected","version":"7.3.13.4"}],"defaultStatus":"affected"}],"descriptions":[{"lang":"en","value":"Abuse of remote unlock in Find My Mobile prior to version 7.3.13.4 allows physical attacker to unlock the device remotely by resetting the Samsung Account password with SMS verification when user lost the device."}],"references":[{"url":"https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=12"}],"metrics":[{"format":"CVSS","cvssV3_1":{"version":"3.1","attackVector":"PHYSICAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseSeverity":"HIGH","baseScore":7.6,"vectorString":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}}],"providerMetadata":{"orgId":"3af57064-a867-422c-b2ad-40307b65c458","shortName":"SamsungMobile","dateUpdated":"2023-12-05T02:44:28.948Z"}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T19:23:39.684Z"},"title":"CVE Program Container","references":[{"url":"https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=12","tags":["x_transferred"]}]},{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2023-12-07T16:41:27.901274Z","id":"CVE-2023-42571","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-12-02T17:12:01.956Z"}}]}}