VendorsSamsungpassall versions
Vulnerabilities

Samsung Pass

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2022-39892
Improper access control in Samsung Pass prior to version 4.0.05.1 allows attackers to unauthenticated access via keep open feature.
Published 2022-11-09 · Modified
9.8EPSS 0.004
CVE-2023-42575
Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication due to invalid flag setting.
Published 2023-12-05 · Modified
6.8EPSS 0.004
CVE-2023-42576
Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication due to invalid exception handler.
Published 2023-12-05 · Modified
6.8EPSS 0.004
CVE-2023-42554
Improper Authentication vulnerabiity in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication.
Published 2023-11-07 · Modified
6.8EPSS 0.003
CVE-2022-39911
Improper check or handling of exceptional conditions vulnerability in Samsung Pass prior to version 4.0.06.1 allows attacker to access Samsung Pass.
Published 2022-12-08 · Modified
6.8EPSS 0.003
CVE-2023-30675
Improper authentication in Samsung Pass prior to version 4.2.03.1 allows local attacker to access stored account information when Samsung Wallet is not installed.
Published 2023-07-06 · Modified
6.2EPSS 0.002
CVE-2023-30677
Improper access control vulnerability in Samsung Pass prior to version 4.2.03.1 allows physical attackers to access data of Samsung Pass on a certain state of an unlocked device.
Published 2023-07-06 · Modified
6.1EPSS 0.003
CVE-2024-49405
Improper authentication in Private Info in Samsung Pass in prior to version 4.4.04.7 allows physical attackers to access sensitive information in a specific scenario.
Published 2024-11-06 · Analyzed
5.3EPSS 0.002
CVE-2023-30676
Improper access control vulnerability in Samsung Pass prior to version 4.2.03.1 allows physical attackers to access data of Samsung Pass.
Published 2023-07-06 · Modified
4.6EPSS 0.003
CVE-2022-39910
Improper access control vulnerability in Samsung Pass prior to version 4.0.06.7 allow physical attackers to access data of Samsung Pass on a certain state of an unlocked device using pop-up view.
Published 2022-12-08 · Modified
4.2EPSS 0.003