CVE-2022-39888 Details
Description
Improper access control vulnerability in retrieveExternalProxy in MiscPolicy prior to SMR Nov-2022 Release 1 allows local attacker to access to Proxy information.
An improper access control vulnerability has been identified in the 'retrieveExternalProxy' function within the MiscPolicy component of Samsung Mobile devices. This vulnerability, present in versions Q(10), R(11), and S(12) prior to the November 2022 Security Maintenance Release, allows local attackers to access proxy information. The issue arises from inadequate access controls, which the latest update addresses by implementing proper permissions to prevent unauthorized access.
Users can apply the November 2022 Security Maintenance Release to address this vulnerability. This update is part of the monthly security update process and includes patches from both Google and Samsung.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 4, 2025CISA-ADP
Assessed Sep 4, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.samsungmobile.com/securityUpdate.smsb?year=2022&month=11 | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Samsung MiscPolicy | Q R S |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 4, 2025 | New CVE Received | [email protected] |
Volerion