Smart Switch
CVEs (22)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-20998 | Cri | 0.64 | 9.8 | 0.01 | Mar 16, 2026 | Improper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authentication. | ||
| CVE-2026-20997 | Cri | 0.64 | 9.8 | 0.00 | Mar 16, 2026 | Improper verification of cryptographic signature in Smart Switch prior to version 3.7.69.15 allows remote attackers to potentially bypass authentication. | ||
| CVE-2025-21078 | Hig | 0.57 | 8.8 | 0.00 | Nov 5, 2025 | Use of insufficiently random value of secretKey in Smart Switch prior to version 3.7.68.6 allows adjacent attackers to access backup data from applications. | ||
| CVE-2025-21064 | Hig | 0.57 | 8.8 | 0.00 | Oct 10, 2025 | Improper authentication in Smart Switch prior to version 3.7.66.6 allows adjacent attackers to access transferring data. | ||
| CVE-2025-21062 | Hig | 0.51 | 7.8 | 0.00 | Oct 10, 2025 | Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.67.2 allows local attackers to replace the restoring application. User interaction is required for triggering this vulnerability. | ||
| CVE-2026-20999 | Hig | 0.49 | 7.5 | 0.00 | Mar 16, 2026 | Authentication bypass by replay in Smart Switch prior to version 3.7.69.15 allows remote attackers to trigger privileged functions. | ||
| CVE-2025-21061 | Hig | 0.46 | 7.1 | 0.00 | Oct 10, 2025 | Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access sensitive data. User interaction is required for triggering this vulnerability. | ||
| CVE-2023-30672 | Med | 0.44 | 6.8 | 0.00 | Jul 6, 2023 | Improper privilege management vulnerability in Samsung Smart Switch for Windows Installer prior to version 4.3.23043_3 allows attackers to cause permanent DoS via directory junction. | ||
| CVE-2026-21083 | Med | 0.42 | 6.5 | 0.00 | Aug 10, 2026 | Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data. | ||
| CVE-2026-21080 | Med | 0.42 | 6.5 | 0.00 | Aug 10, 2026 | Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data. | ||
| CVE-2026-21079 | Med | 0.42 | 6.5 | 0.00 | Aug 10, 2026 | Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data. | ||
| CVE-2026-21078 | Med | 0.42 | 6.5 | 0.00 | Aug 10, 2026 | Insufficient verification of data authenticity in Smart Switch trouble scanning mode prior to version 3.7.72.6 allows adjacent attackers to spoof device identity. | ||
| CVE-2026-21005 | Med | 0.42 | 6.5 | 0.00 | Mar 16, 2026 | Path traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Smart Switch privilege. | ||
| CVE-2026-21004 | Med | 0.42 | 6.5 | 0.00 | Mar 16, 2026 | Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of service. | ||
| CVE-2022-39846 | Med | 0.40 | 6.2 | 0.00 | Sep 9, 2022 | DLL hijacking vulnerability in Smart Switch PC prior to version 4.3.22083_3 allows attacker to execute arbitrary code. | ||
| CVE-2022-27842 | Med | 0.40 | 6.2 | 0.00 | Apr 11, 2022 | DLL hijacking vulnerability in Smart Switch PC prior to version 4.2.22022_4 allows attacker to execute abitrary code. | ||
| CVE-2025-21060 | Med | 0.36 | 5.5 | 0.00 | Oct 10, 2025 | Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access backup data from applications. User interaction is required for triggering this vulnerability. | ||
| CVE-2023-30673 | Med | 0.36 | 5.5 | 0.00 | Jul 6, 2023 | Improper validation of integrity check vulnerability in Smart Switch PC prior to version 4.3.23052_1 allows local attackers to delete arbitrary directory using directory junction. | ||
| CVE-2022-39844 | Med | 0.36 | 5.5 | 0.00 | Sep 9, 2022 | Improper validation of integrity check vulnerability in Smart Switch PC prior to version 4.3.22083 allows local attackers to delete arbitrary directory using directory junction. | ||
| CVE-2026-20996 | Med | 0.34 | 5.3 | 0.00 | Mar 16, 2026 | Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.69.15 allows remote attackers to configure a downgraded scheme for authentication. |
- risk 0.64cvss 9.8epss 0.01
Improper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authentication.
- risk 0.64cvss 9.8epss 0.00
Improper verification of cryptographic signature in Smart Switch prior to version 3.7.69.15 allows remote attackers to potentially bypass authentication.
- risk 0.57cvss 8.8epss 0.00
Use of insufficiently random value of secretKey in Smart Switch prior to version 3.7.68.6 allows adjacent attackers to access backup data from applications.
- risk 0.57cvss 8.8epss 0.00
Improper authentication in Smart Switch prior to version 3.7.66.6 allows adjacent attackers to access transferring data.
- risk 0.51cvss 7.8epss 0.00
Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.67.2 allows local attackers to replace the restoring application. User interaction is required for triggering this vulnerability.
- risk 0.49cvss 7.5epss 0.00
Authentication bypass by replay in Smart Switch prior to version 3.7.69.15 allows remote attackers to trigger privileged functions.
- risk 0.46cvss 7.1epss 0.00
Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access sensitive data. User interaction is required for triggering this vulnerability.
- risk 0.44cvss 6.8epss 0.00
Improper privilege management vulnerability in Samsung Smart Switch for Windows Installer prior to version 4.3.23043_3 allows attackers to cause permanent DoS via directory junction.
- risk 0.42cvss 6.5epss 0.00
Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.
- risk 0.42cvss 6.5epss 0.00
Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.
- risk 0.42cvss 6.5epss 0.00
Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data.
- risk 0.42cvss 6.5epss 0.00
Insufficient verification of data authenticity in Smart Switch trouble scanning mode prior to version 3.7.72.6 allows adjacent attackers to spoof device identity.
- risk 0.42cvss 6.5epss 0.00
Path traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Smart Switch privilege.
- risk 0.42cvss 6.5epss 0.00
Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of service.
- risk 0.40cvss 6.2epss 0.00
DLL hijacking vulnerability in Smart Switch PC prior to version 4.3.22083_3 allows attacker to execute arbitrary code.
- risk 0.40cvss 6.2epss 0.00
DLL hijacking vulnerability in Smart Switch PC prior to version 4.2.22022_4 allows attacker to execute abitrary code.
- risk 0.36cvss 5.5epss 0.00
Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access backup data from applications. User interaction is required for triggering this vulnerability.
- risk 0.36cvss 5.5epss 0.00
Improper validation of integrity check vulnerability in Smart Switch PC prior to version 4.3.23052_1 allows local attackers to delete arbitrary directory using directory junction.
- risk 0.36cvss 5.5epss 0.00
Improper validation of integrity check vulnerability in Smart Switch PC prior to version 4.3.22083 allows local attackers to delete arbitrary directory using directory junction.
- risk 0.34cvss 5.3epss 0.00
Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.69.15 allows remote attackers to configure a downgraded scheme for authentication.
Page 1 of 2