VYPR

Smart Switch

by Samsung Mobile

CVEs (22)

  • CVE-2026-20998CriMar 16, 2026
    risk 0.64cvss 9.8epss 0.01

    Improper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authentication.

  • CVE-2026-20997CriMar 16, 2026
    risk 0.64cvss 9.8epss 0.00

    Improper verification of cryptographic signature in Smart Switch prior to version 3.7.69.15 allows remote attackers to potentially bypass authentication.

  • CVE-2025-21078HigNov 5, 2025
    risk 0.57cvss 8.8epss 0.00

    Use of insufficiently random value of secretKey in Smart Switch prior to version 3.7.68.6 allows adjacent attackers to access backup data from applications.

  • CVE-2025-21064HigOct 10, 2025
    risk 0.57cvss 8.8epss 0.00

    Improper authentication in Smart Switch prior to version 3.7.66.6 allows adjacent attackers to access transferring data.

  • CVE-2025-21062HigOct 10, 2025
    risk 0.51cvss 7.8epss 0.00

    Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.67.2 allows local attackers to replace the restoring application. User interaction is required for triggering this vulnerability.

  • CVE-2026-20999HigMar 16, 2026
    risk 0.49cvss 7.5epss 0.00

    Authentication bypass by replay in Smart Switch prior to version 3.7.69.15 allows remote attackers to trigger privileged functions.

  • CVE-2025-21061HigOct 10, 2025
    risk 0.46cvss 7.1epss 0.00

    Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access sensitive data. User interaction is required for triggering this vulnerability.

  • CVE-2023-30672MedJul 6, 2023
    risk 0.44cvss 6.8epss 0.00

    Improper privilege management vulnerability in Samsung Smart Switch for Windows Installer prior to version 4.3.23043_3 allows attackers to cause permanent DoS via directory junction.

  • CVE-2026-21083MedAug 10, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.

  • CVE-2026-21080MedAug 10, 2026
    risk 0.42cvss 6.5epss 0.00

    Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.

  • CVE-2026-21079MedAug 10, 2026
    risk 0.42cvss 6.5epss 0.00

    Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data.

  • CVE-2026-21078MedAug 10, 2026
    risk 0.42cvss 6.5epss 0.00

    Insufficient verification of data authenticity in Smart Switch trouble scanning mode prior to version 3.7.72.6 allows adjacent attackers to spoof device identity.

  • CVE-2026-21005MedMar 16, 2026
    risk 0.42cvss 6.5epss 0.00

    Path traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Smart Switch privilege.

  • CVE-2026-21004MedMar 16, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of service.

  • CVE-2022-39846MedSep 9, 2022
    risk 0.40cvss 6.2epss 0.00

    DLL hijacking vulnerability in Smart Switch PC prior to version 4.3.22083_3 allows attacker to execute arbitrary code.

  • CVE-2022-27842MedApr 11, 2022
    risk 0.40cvss 6.2epss 0.00

    DLL hijacking vulnerability in Smart Switch PC prior to version 4.2.22022_4 allows attacker to execute abitrary code.

  • CVE-2025-21060MedOct 10, 2025
    risk 0.36cvss 5.5epss 0.00

    Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access backup data from applications. User interaction is required for triggering this vulnerability.

  • CVE-2023-30673MedJul 6, 2023
    risk 0.36cvss 5.5epss 0.00

    Improper validation of integrity check vulnerability in Smart Switch PC prior to version 4.3.23052_1 allows local attackers to delete arbitrary directory using directory junction.

  • CVE-2022-39844MedSep 9, 2022
    risk 0.36cvss 5.5epss 0.00

    Improper validation of integrity check vulnerability in Smart Switch PC prior to version 4.3.22083 allows local attackers to delete arbitrary directory using directory junction.

  • CVE-2026-20996MedMar 16, 2026
    risk 0.34cvss 5.3epss 0.00

    Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.69.15 allows remote attackers to configure a downgraded scheme for authentication.

Page 1 of 2