{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-20854","assignerOrgId":"3af57064-a867-422c-b2ad-40307b65c458","state":"PUBLISHED","assignerShortName":"SamsungMobile","dateReserved":"2023-12-05T04:57:52.539Z","datePublished":"2024-04-02T02:59:50.530Z","dateUpdated":"2024-08-01T22:06:36.824Z"},"containers":{"cna":{"problemTypes":[{"descriptions":[{"lang":"en","description":"CWE-280: Improper Handling of Insufficient Permissions or Privileges"}]}],"affected":[{"vendor":"Samsung Mobile","product":"Samsung Camera","versions":[{"status":"unaffected","version":"12.1.0.31 in Android 12, 13.1.02.07 in Android 13, and 14.0.01.06 in Android 14"}],"defaultStatus":"affected"}],"descriptions":[{"lang":"en","value":"Improper handling of insufficient privileges vulnerability in Samsung Camera prior to versions 12.1.0.31 in Android 12, 13.1.02.07 in Android 13, and 14.0.01.06 in Android 14 allows local attackers to access image data."}],"references":[{"url":"https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=04"}],"metrics":[{"format":"CVSS","cvssV3_1":{"version":"3.1","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseSeverity":"MEDIUM","baseScore":5.9,"vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"}}],"providerMetadata":{"orgId":"3af57064-a867-422c-b2ad-40307b65c458","shortName":"SamsungMobile","dateUpdated":"2024-04-02T02:59:50.530Z"}},"adp":[{"title":"CISA ADP Vulnrichment","metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2024-20854","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2024-04-02T14:59:54.144575Z"}}}],"providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-06-04T17:40:43.514Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-01T22:06:36.824Z"},"title":"CVE Program Container","references":[{"url":"https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=04","tags":["x_transferred"]}]}]}}