CVE-2021-25507

Improper authorization vulnerability in Samsung Flow mobile application prior to 4.8.03.5 allows Samsung Flow PC application connected with user device to access part of notification data in Secure Folder without authorization.
Configurations

Configuration 1 (hide)

cpe:2.3:a:samsung:samsung_flow:*:*:*:*:*:android:*:*

History

14 Jul 2022, 17:52

Type Values Removed Values Added
CWE CWE-863 NVD-CWE-Other

09 Nov 2021, 15:54

Type Values Removed Values Added
CWE CWE-863
CVSS v2 : unknown
v3 : unknown
v2 : 2.7
v3 : 5.7
References (MISC) https://security.samsungmobile.com/serviceWeb.smsb?year=2021&month=11 - (MISC) https://security.samsungmobile.com/serviceWeb.smsb?year=2021&month=11 - Vendor Advisory
CPE cpe:2.3:a:samsung:samsung_flow:*:*:*:*:*:android:*:*

05 Nov 2021, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-11-05 03:15

Updated : 2024-02-04 22:08


NVD link : CVE-2021-25507

Mitre link : CVE-2021-25507

CVE.ORG link : CVE-2021-25507


JSON object : View

Products Affected

samsung

  • samsung_flow
CWE
NVD-CWE-Other CWE-285

Improper Authorization