SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-30678

Potential zip path traversal vulnerability in Calendar application prior to version 12.4.07.15 in Android 13 allows attackers to write arbitrary file.

MEDIUM 5.5EPSS 0.20%

Does this matter?

Lower severity and a low EPSS score (0.20%). Track it; it rarely justifies an emergency change on its own.

Description

Potential zip path traversal vulnerability in Calendar application prior to version 12.4.07.15 in Android 13 allows attackers to write arbitrary file.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS
0.20% probability · 11th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
samsung/calendar
Source
mobile.security@samsung.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.