CVE-2024-49404 is an improper access control vulnerability in Samsung Video Player versions prior to 7.3.29.1 (Android 12), 7.3.36.1 (Android 13), and 7.3.41.230 (Android 14), allowing physical attackers to access other users' video files. With a CVSS score of 4.6 (Medium), this vulnerability requires physical access to the device and has low attack complexity, primarily impacting confidentiality. There is no evidence of active exploitation, public exploit code, or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.3.29.1CPE matchmatch criteria | cpe:2.3:a:samsung:video_player:*:*:*:*:*:*:*:* | ||
< 7.3.36.1CPE matchmatch criteria | cpe:2.3:a:samsung:video_player:*:*:*:*:*:*:*:* | ||
< 7.3.41.230CPE matchmatch criteria | cpe:2.3:a:samsung:video_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.