CVE-2021-25373

Using unsafe PendingIntent in Customization Service prior to version 2.2.02.1 in Android O(8.x), 2.4.03.0 in Android P(9.0), 2.7.02.1 in Android Q(10.0) and 2.9.01.1 in Android R(11.0) allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:samsung:customization_service:*:*:*:*:*:*:*:*
OR cpe:2.3:o:google:android:8.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:8.1:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:samsung:customization_service:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:9.0:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:a:samsung:customization_service:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:a:samsung:customization_service:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*

History

21 Nov 2024, 05:54

Type Values Removed Values Added
References () https://security.samsungmobile.com/ - Vendor Advisory () https://security.samsungmobile.com/ - Vendor Advisory
References () https://security.samsungmobile.com/serviceWeb.smsb - Vendor Advisory () https://security.samsungmobile.com/serviceWeb.smsb - Vendor Advisory
CVSS v2 : 4.6
v3 : 7.8
v2 : 4.6
v3 : 5.5

12 Aug 2022, 18:02

Type Values Removed Values Added
CWE CWE-863 NVD-CWE-noinfo

Information

Published : 2021-04-09 18:15

Updated : 2024-11-21 05:54


NVD link : CVE-2021-25373

Mitre link : CVE-2021-25373

CVE.ORG link : CVE-2021-25373


JSON object : View

Products Affected

samsung

  • customization_service

google

  • android
CWE
CWE-285

Improper Authorization

NVD-CWE-noinfo