Tizen

Vendor:

First CVE: Jan 1, 2013 · Active for 13 years

13
Total CVEs
More Total CVEs than 91% of tracked products
4.3
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 62% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Tizen over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 1, 2013
13 years ago
Most Recent CVE
Jul 8, 2021
1,842 days ago

CVE Severity & Scoring

Tizen13 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local1 (7.7%)
Network4 (30.8%)
Unknown1 (7.7%)
Physical0 (0.0%)
Adjacent Network7 (53.8%)
Attack Complexity
Low12 (92.3%)
High0 (0.0%)
Unknown1 (7.7%)
User Interaction
None12 (92.3%)
Unknown1 (7.7%)
Required0 (0.0%)
Privileges Required
Low1 (7.7%)
High0 (0.0%)
None11 (84.6%)
Unknown1 (7.7%)

Top CVEs

Signals from CVEs in this product scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Improper access control vulnerability in Tizen FOTA service prior to Firmware update JUL-2021 Release allows attackers to arbitrary code execution by replacing FOTA update file.
Jul 8, 20219.829NONO
Improper input validation vulnerability in Tizen FOTA service prior to Firmware update JUL-2021 Release allows arbitrary code execution via Samsung Accessory Protocol.
Jul 8, 20219.829NONO
Improper input validation vulnerability in Tizen bootloader prior to Firmware update JUL-2021 Release allows arbitrary code execution using recovery partition in wireless firmware
Jul 8, 20219.829NONO
Improper input validation vulnerability in Tizen bootloader prior to Firmware update JUL-2021 Release allows arbitrary code execution using param partition in wireless firmware dow
Jul 8, 20219.829NONO
The PulseAudio system service in Tizen allows an unprivileged process to control its A2DP MediaEndpoint, due to improper D-Bus security policy configurations. This affects Tizen be
Jan 22, 20208.825NONO
The pkgmgr system service in Tizen allows an unprivileged process to perform package management actions, due to improper D-Bus security policy configurations. Such actions include
Jan 22, 20208.825NONO
The system-popup system service in Tizen allows an unprivileged process to perform popup-related system actions, due to improper D-Bus security policy configurations. Such actions
Jan 22, 20208.124NONO
The Enlightenment system service in Tizen allows an unprivileged process to fully control or capture windows, due to improper D-Bus security policy configurations. This affects Tiz
Jan 22, 20208.124NONO
Improper authorization vulnerability in Tizen factory reset policy prior to Firmware update JUL-2021 Release allows untrusted applications to perform factory reset using dbus signa
Jul 8, 20215.520NONO
The bt/bt_core system service in Tizen allows an unprivileged process to create a system user interface and control the Bluetooth pairing process, due to improper D-Bus security po
Jan 22, 20206.520NONO

Exploit Exposure

Signals from CVEs in this product scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (13 CVEs).

Media Mentions

Signals from CVEs in this product scope (13 CVEs).

Top CNAs Publishing CVEs For Tizen

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.077.30.7%00
4.077.30.7%00
3.077.30.7%00
2.477.30.7%00
2.3.177.30.7%00
2.377.30.7%00
2.2.177.30.7%00
2.277.30.7%00
2.177.30.7%00
2.077.30.7%00
1.077.30.7%00