Technical Severity
MEDIUM
CVSS v3.1 Metrics
4.4
/ 10
Minimal Risk
Critical
Vector Specification
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Exploitation Likelihood
EPSS Prediction
0.30
%
Predictive Probability
Percentile Rank
52.5
th
Documented as more likely to be exploited than 52.5% of known CVEs.
Detection Date
Nov 08, 2022
Remediation Due
Nov 29, 2022
CISA Catalog Active
Threat Analysis
Samsung mobile devices contain an improper access control vulnerability in clipboard service which allows untrusted applications to read or write arbitrary files. This vulnerability was chained with CVE-2021-25369 and CVE-2021-25370.
Remediation Directive
Apply updates per vendor instructions.