Vulnerability Description
The Samsung TV (2021 and 2022 model) smart remote control allows attackers to enable microphone access via Bluetooth spoofing when a user is activating remote control by pressing a button. This is fixed in xxx72510, E9172511 for 2021 models, xxxA1000, 4x2A0200 for 2022 models.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Samsung | T-Oscpakuc Firmware | - |
| Samsung | T-Oscpakuc | - |
| Samsung | T-Oscpdeuc Firmware | - |
| Samsung | T-Oscpdeuc | - |
| Samsung | T-Oscpuabc Firmware | - |
| Samsung | T-Oscpuabc | - |
| Samsung | T-Nkm2Akuc Firmware | - |
| Samsung | T-Nkm2Akuc | - |
| Samsung | T-Nkm2Deuc Firmware | - |
| Samsung | T-Nkm2Deuc | - |
| Samsung | T-Nkm2Uabc Firmware | - |
| Samsung | T-Nkm2Uabc | - |
| Samsung | T-Nklakuc Firmware | - |
| Samsung | T-Nklakuc | - |
| Samsung | T-Nkldeuc Firmware | - |
| Samsung | T-Nkldeuc | - |
| Samsung | T-Nkluabc Firmware | - |
| Samsung | T-Nkluabc | - |
| Samsung | T-Ksu2Eakuc Firmware | - |
| Samsung | T-Ksu2Eakuc | - |
Related Weaknesses (CWE)
References
- https://samsung.comVendor Advisory
- https://samsungtvbounty.com/securityUpdatesVendor Advisory
- https://samsung.comVendor Advisory
- https://samsungtvbounty.com/securityUpdatesVendor Advisory
FAQ
What is CVE-2022-44636?
CVE-2022-44636 is a vulnerability with a CVSS score of 4.6 (MEDIUM). The Samsung TV (2021 and 2022 model) smart remote control allows attackers to enable microphone access via Bluetooth spoofing when a user is activating remote control by pressing a button. This is fix...
How severe is CVE-2022-44636?
CVE-2022-44636 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-44636?
Check the references section above for vendor advisories and patch information. Affected products include: Samsung T-Oscpakuc Firmware, Samsung T-Oscpakuc, Samsung T-Oscpdeuc Firmware, Samsung T-Oscpdeuc, Samsung T-Oscpuabc Firmware.