| |
Vulnerability CVE-2021-25507
Published: 2021-11-05
Description: |
Improper authorization vulnerability in Samsung Flow mobile application prior to 4.8.03.5 allows Samsung Flow PC application connected with user device to access part of notification data in Secure Folder without authorization. |
Type:
CWE-863 (Incorrect Authorization)
CVSS2 => (AV:A/AC:L/Au:S/C:P/I:N/A:N)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
2.7/10 |
2.9/10 |
5.1/10 |
Exploit range |
Attack complexity |
Authentication |
Adjacent network |
Low |
Single time |
Confidentiality impact |
Integrity impact |
Availability impact |
Partial |
None |
None |
References: |
https://security.samsungmobile.com/serviceWeb.smsb?year=2021&month=11
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|