Home
MEDIUM: 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:LDefault status
unaffected
2.0.0 (custom) before 2.3.13.1
affected
2.5.0.17 (custom) before 2.6.14.1
affected
2.7.0.15 (custom) before 2.9.3.6
affected
Description
An execution after redirect in Samsung DMS(Data Management Server) allows attackers to execute limited functions without permissions. An attacker could compromise the integrity of the platform by executing this vulnerability.
Problem types
CWE-698 Execution After Redirect (EAR)
Product status
2.0.0 (custom) before 2.3.13.1
2.5.0.17 (custom) before 2.6.14.1
2.7.0.15 (custom) before 2.9.3.6
Credits
Noam Moshe of Claroty Team82
References
security.samsungda.com/securityUpdates.html