
CVE-2023-21421
https://notcve.org/view.php?id=CVE-2023-21421
09 Feb 2023 — Improper Handling of Insufficient Permissions or Privileges vulnerability in KnoxCustomManagerService prior to SMR Jan-2023 Release 1 allows attacker to access device SIM PIN. • https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=01 • CWE-269: Improper Privilege Management CWE-280: Improper Handling of Insufficient Permissions or Privileges •

CVE-2023-21439
https://notcve.org/view.php?id=CVE-2023-21439
09 Feb 2023 — Improper input validation vulnerability in UwbDataTxStatusEvent prior to SMR Feb-2023 Release 1 allows attackers to launch certain activities. • https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=02 • CWE-20: Improper Input Validation •

CVE-2023-21422
https://notcve.org/view.php?id=CVE-2023-21422
09 Feb 2023 — Improper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attackers to set custom DNS server without permission via binding WifiService. • https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=01 • CWE-285: Improper Authorization CWE-863: Incorrect Authorization •

CVE-2023-21442
https://notcve.org/view.php?id=CVE-2023-21442
09 Feb 2023 — Improper access control vulnerability in Runestone application prior to version 2.9.09.003 in Android R(11) and 3.2.01.007 in Android S(12) allows local attackers to get device location information. • https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=02 • CWE-284: Improper Access Control •

CVE-2023-21445
https://notcve.org/view.php?id=CVE-2023-21445
09 Feb 2023 — Improper access control vulnerability in MyFiles prior to versions 12.2.09 in Android R(11), 13.1.03.501 in Android S(12) and 14.1.00.422 in Android T(13) allows local attacker to write file with MyFiles privilege via implicit intent. • https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=02 • CWE-284: Improper Access Control CWE-668: Exposure of Resource to Wrong Sphere •

CVE-2023-21446
https://notcve.org/view.php?id=CVE-2023-21446
09 Feb 2023 — Improper input validation in MyFiles prior to version 12.2.09 in Android R(11), 13.1.03.501 in Android S( 12) and 14.1.00.422 in Android T(13) allows local attacker to access data of MyFiles. • https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=02 • CWE-20: Improper Input Validation •

CVE-2023-21427
https://notcve.org/view.php?id=CVE-2023-21427
09 Feb 2023 — Improper access control vulnerability in NfcTile prior to SMR Jan-2023 Release 1 allows to attacker to use NFC without user recognition. • https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=01 • CWE-284: Improper Access Control •

CVE-2023-21435
https://notcve.org/view.php?id=CVE-2023-21435
09 Feb 2023 — Exposure of Sensitive Information vulnerability in Fingerprint TA prior to SMR Feb-2023 Release 1 allows attackers to access the memory address information via log. • https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=02 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-532: Insertion of Sensitive Information into Log File •

CVE-2023-21430
https://notcve.org/view.php?id=CVE-2023-21430
09 Feb 2023 — An out-of-bound read vulnerability in mapToBuffer function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR JAN-2023 Release 1 allows attacker to cause memory access fault. • https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=01 • CWE-125: Out-of-bounds Read •

CVE-2023-21440
https://notcve.org/view.php?id=CVE-2023-21440
09 Feb 2023 — Improper access control vulnerability in WindowManagerService prior to SMR Feb-2023 Release 1 allows attackers to take a screen capture. • https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=02 • CWE-285: Improper Authorization CWE-829: Inclusion of Functionality from Untrusted Control Sphere •