SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-44636

The Samsung TV (2021 and 2022 model) smart remote control allows attackers to enable microphone access via Bluetooth spoofing when a user is activating remote control by pressing a button.

MEDIUM 4.6EPSS 0.25%

Does this matter?

Lower severity and a low EPSS score (0.25%). Track it; it rarely justifies an emergency change on its own.

Description

The Samsung TV (2021 and 2022 model) smart remote control allows attackers to enable microphone access via Bluetooth spoofing when a user is activating remote control by pressing a button. This is fixed in xxx72510, E9172511 for 2021 models, xxxA1000, 4x2A0200 for 2022 models.

CVSS 3.1
4.6 MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
EPSS
0.25% probability · 16th percentile
CISA KEV
Not listed
Weakness
CWE-290
Affected
samsung/t-oscpakuc firmware · samsung/t-oscpdeuc firmware · samsung/t-oscpuabc firmware · samsung/t-nkm2akuc firmware · samsung/t-nkm2deuc firmware · samsung/t-nkm2uabc firmware · samsung/t-nklakuc firmware · samsung/t-nkldeuc firmware · samsung/t-nkluabc firmware · samsung/t-ksu2eakuc firmware · samsung/t-ksu2edeuc firmware · samsung/t-ksu2euab firmware · samsung/t-ptmakuc firmware · samsung/t-ptmdeuc firmware · samsung/t-ptmuabc firmware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.