Improper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attackers to set custom DNS server without permission via binding WifiService.
References
Link | Resource |
---|---|
https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=01 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2023-02-09 11:15
Updated : 2023-02-21 08:13
NVD link : CVE-2023-21422
Mitre link : CVE-2023-21422
JSON object : View
CWE
CWE-863
Incorrect Authorization
Products Affected
samsung
- android