{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-20839","assignerOrgId":"3af57064-a867-422c-b2ad-40307b65c458","state":"PUBLISHED","assignerShortName":"SamsungMobile","dateReserved":"2023-12-05T04:57:52.535Z","datePublished":"2024-03-05T04:44:48.626Z","dateUpdated":"2024-08-01T22:06:36.398Z"},"containers":{"cna":{"problemTypes":[{"descriptions":[{"lang":"en","description":"CWE-284: Improper Access Control"}]}],"affected":[{"vendor":"Samsung Mobile","product":"Samsung Voice Recorder","versions":[{"status":"unaffected","version":"21.5.16.01 in Android 12 and Android 13, 21.4.51.02 in Android 14"}],"defaultStatus":"affected"}],"descriptions":[{"lang":"en","value":"Improper access control in Samsung Voice Recorder prior to versions 21.5.16.01 in Android 12 and Android 13, 21.4.51.02 in Android 14 allows physical attackers to access recording files on the lock screen."}],"references":[{"url":"https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=03"}],"metrics":[{"format":"CVSS","cvssV3_1":{"version":"3.1","attackVector":"PHYSICAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseSeverity":"MEDIUM","baseScore":4.6,"vectorString":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}}],"providerMetadata":{"orgId":"3af57064-a867-422c-b2ad-40307b65c458","shortName":"SamsungMobile","dateUpdated":"2024-03-05T04:44:48.626Z"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-07-25T17:03:15.333556Z","id":"CVE-2024-20839","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-07-25T17:03:20.887Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-01T22:06:36.398Z"},"title":"CVE Program Container","references":[{"url":"https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=03","tags":["x_transferred"]}]}]}}