samsung smartthings CVE Vulnerabilities (17)

CVEs: 17 CPE versions: View versions table

Summary

This page lists publicly disclosed CVE vulnerabilities affecting samsung smartthings (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.

Showing 117 of 17 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-2233 Samsung SmartThings Improper Verification of Cryptographic Signature Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Samsung SmartThings. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Hub Local API service, which listens on TCP port 8766 by default. The issue results from the lack of proper verification of a cryptographic signature. An attacker can [email protected] 8.8 0.04% 2025-03-11 2025-08-08
CVE-2024-49416 Use of implicit intent for sensitive communication in SmartThings prior to version 1.8.21 allows local attackers to get sensitive information. [email protected] 4.0 0.07% 2024-12-03 2025-07-17
CVE-2024-34596 Improper authentication in SmartThings prior to version 1.8.17 allows remote attackers to bypass the expiration date for members set by the owner. [email protected] 5.9 0.27% 2024-07-02 2024-11-21
CVE-2024-20852 Improper verification of intent by broadcast receiver vulnerability in SmartThings prior to version 1.8.13.22 allows local attackers to access testing configuration. [email protected] 5.9 0.06% 2024-04-02 2025-07-17
CVE-2022-39871 Improper access control vulnerability cloudNotificationManager.java in SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcasts. [email protected] 4.0 0.24% 2022-10-07 2024-11-21
CVE-2022-39870 Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via PUSH_MESSAGE_RECEIVED broadcast. [email protected] 4.0 0.24% 2022-10-07 2024-11-21
CVE-2022-39869 Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via REMOVE_PERSISTENT_BANNER broadcast. [email protected] 4.0 0.24% 2022-10-07 2024-11-21
CVE-2022-39868 Improper access control vulnerability in GedSamsungAccount.kt SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast. [email protected] 4.0 0.24% 2022-10-07 2024-11-21
CVE-2022-39867 Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via SHOW_PERSISTENT_BANNER broadcast. [email protected] 4.0 0.24% 2022-10-07 2024-11-21
CVE-2022-39866 Improper access control vulnerability in RegisteredEventMediator.kt SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast. [email protected] 4.0 0.24% 2022-10-07 2024-11-21
CVE-2022-39865 Improper access control vulnerability in ContentsSharingActivity.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast. [email protected] 4.0 0.24% 2022-10-07 2024-11-21
CVE-2022-39864 Improper access control vulnerability in WifiSetupLaunchHelper in SmartThings prior to version 1.7.89.25 allows attackers to access sensitive information via implicit intent. [email protected] 3.3 0.24% 2022-10-07 2024-11-21
CVE-2022-30749 Improper access control vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to add arbitrary smart devices by bypassing login activity. [email protected] 3.3 0.05% 2022-06-07 2024-11-21
CVE-2022-30747 PendingIntent hijacking vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to access files without permission via implicit Intent. [email protected] 5.5 0.05% 2022-06-07 2024-11-21
CVE-2022-30746 Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely using javascript interface API. [email protected] 7.5 0.34% 2022-06-07 2024-11-21
CVE-2021-25508 Improper privilege management vulnerability in API Key used in SmartThings prior to 1.7.73.22 allows an attacker to abuse the API key without limitation. [email protected] 5.3 0.27% 2021-11-05 2024-11-21
CVE-2021-25378 Improper access control of certain port in SmartThings prior to version 1.7.63.6 allows remote temporary denial of service. [email protected] 4.3 0.39% 2021-04-09 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence