Flow
CVEs (9)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-21443 | Hig | 0.49 | 7.5 | 0.00 | Feb 9, 2023 | Improper cryptographic implementation in Samsung Flow for Android prior to version 4.9.04 allows adjacent attackers to decrypt encrypted messages or inject commands. | ||
| CVE-2025-20972 | Med | 0.40 | 6.2 | 0.00 | May 7, 2025 | Improper verification of intent by broadcast receiver in Samsung Flow prior to version 4.9.17.6 allows local attackers to modify Samsung Flow configuration. | ||
| CVE-2021-25509 | Med | 0.38 | 5.9 | 0.00 | Nov 5, 2021 | A missing input validation in Samsung Flow Windows application prior to Version 4.8.5.0 allows attackers to overwrite abtraty file in the Windows known folders. | ||
| CVE-2021-25507 | Med | 0.37 | 5.7 | 0.00 | Nov 5, 2021 | Improper authorization vulnerability in Samsung Flow mobile application prior to 4.8.03.5 allows Samsung Flow PC application connected with user device to access part of notification data in Secure Folder without authorization. | ||
| CVE-2025-20971 | Med | 0.36 | 5.5 | 0.00 | May 7, 2025 | Improper input validation in Samsung Flow prior to version 4.9.17.6 allows local attackers to access data within Samsung Flow. | ||
| CVE-2022-28775 | Med | 0.33 | 5.1 | 0.00 | Apr 11, 2022 | Improper access control vulnerability in Samsung Flow prior to version 4.8.06.5 allows attacker to write the file without Samsung Flow permission. | ||
| CVE-2024-49407 | Med | 0.30 | 4.6 | 0.00 | Nov 6, 2024 | Improper access control in Samsung Flow prior to version 4.9.15.7 allows physical attackers to access data across multiple user profiles. | ||
| CVE-2024-34600 | Med | 0.29 | 4.4 | 0.00 | Jul 2, 2024 | Improper verification of intent by broadcast receiver vulnerability in Samsung Flow prior to version 4.9.13.0 allows local attackers to copy image files to external storage. | ||
| CVE-2022-28543 | Med | 0.26 | 4.0 | 0.00 | Apr 11, 2022 | Path traversal vulnerability in Samsung Flow prior to version 4.8.07.4 allows local attackers to read arbitrary files as Samsung Flow permission. |
- risk 0.49cvss 7.5epss 0.00
Improper cryptographic implementation in Samsung Flow for Android prior to version 4.9.04 allows adjacent attackers to decrypt encrypted messages or inject commands.
- risk 0.40cvss 6.2epss 0.00
Improper verification of intent by broadcast receiver in Samsung Flow prior to version 4.9.17.6 allows local attackers to modify Samsung Flow configuration.
- risk 0.38cvss 5.9epss 0.00
A missing input validation in Samsung Flow Windows application prior to Version 4.8.5.0 allows attackers to overwrite abtraty file in the Windows known folders.
- risk 0.37cvss 5.7epss 0.00
Improper authorization vulnerability in Samsung Flow mobile application prior to 4.8.03.5 allows Samsung Flow PC application connected with user device to access part of notification data in Secure Folder without authorization.
- risk 0.36cvss 5.5epss 0.00
Improper input validation in Samsung Flow prior to version 4.9.17.6 allows local attackers to access data within Samsung Flow.
- risk 0.33cvss 5.1epss 0.00
Improper access control vulnerability in Samsung Flow prior to version 4.8.06.5 allows attacker to write the file without Samsung Flow permission.
- risk 0.30cvss 4.6epss 0.00
Improper access control in Samsung Flow prior to version 4.9.15.7 allows physical attackers to access data across multiple user profiles.
- risk 0.29cvss 4.4epss 0.00
Improper verification of intent by broadcast receiver vulnerability in Samsung Flow prior to version 4.9.13.0 allows local attackers to copy image files to external storage.
- risk 0.26cvss 4.0epss 0.00
Path traversal vulnerability in Samsung Flow prior to version 4.8.07.4 allows local attackers to read arbitrary files as Samsung Flow permission.