CVE-2024-20840
2.4
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Exploitability: 0.9 / Impact: 1.4
Source: NVD
Description
Improper access control in Samsung Voice Recorder prior to versions 21.5.16.01 in Android 12 and Android 13, 21.4.51.02 in Android 14 allows physical attackers using hardware keyboard to use VoiceRecorder on the lock screen.
Affected (2)
Products: Samsung: Voice Recorder
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 21.5.16.01 |
| Running on/with | Platform Versions |
|---|---|
Google Android | Version 12.0 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 21.4.51.02 |
| Running on/with | Platform Versions |
|---|---|
Google Android | Version 14.0 |
References (2)
Source: mobile.security@samsung.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.