
Cloud Vulnerability DB
A community-led vulnerabilities database
Improper export of android application components vulnerability in TelephonyUI prior to SMR May-2024 Release 1 allows local attackers to reboot the device without proper permission. The vulnerability was discovered and reported on May 7, 2024, and was assigned CVE-2024-20860 by Samsung Mobile (Samsung Advisory).
The vulnerability has been assigned a CVSS v3.1 Base Score of 3.3 (LOW) by NIST with vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L. Samsung Mobile assigned a slightly higher CVSS score of 4.0 (MEDIUM) with vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L. The vulnerability affects Samsung Android devices running version 14.0 and its various security patch levels (NVD).
If exploited, this vulnerability allows local attackers to reboot the device without having the proper permissions. This primarily affects the availability of the device, as indicated by the CVSS metrics showing impact only on availability (A:L) with no impact on confidentiality or integrity (NVD).
The vulnerability requires local access (AV:L) with low attack complexity (AC:L). According to NIST's assessment, it requires low privileges (PR:L) and no user interaction (UI:N) to exploit. However, Samsung's assessment indicates no privileges are required (PR:N) (NVD).
The vulnerability has been patched in the Samsung Mobile Security Maintenance Release (SMR) May-2024 Release 1. Users should update their devices to this security patch level or later to mitigate the vulnerability (Samsung Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."