MEDIUM · 4.9

CVE-2024-20871

Improper authorization vulnerability in Samsung Keyboard prior to version One UI 5.1.1 allows physical attackers to partially bypass the factory reset protection.

Vulnerability Description

Improper authorization vulnerability in Samsung Keyboard prior to version One UI 5.1.1 allows physical attackers to partially bypass the factory reset protection.

CVSS Score

4.9

MEDIUM

CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
LOW

Affected Products

VendorProductVersions
SamsungOne Ui< 5.1.1

References

FAQ

What is CVE-2024-20871?

CVE-2024-20871 is a vulnerability with a CVSS score of 4.9 (MEDIUM). Improper authorization vulnerability in Samsung Keyboard prior to version One UI 5.1.1 allows physical attackers to partially bypass the factory reset protection.

How severe is CVE-2024-20871?

CVE-2024-20871 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-20871?

Check the references section above for vendor advisories and patch information. Affected products include: Samsung One Ui.