Improper authorization vulnerability in Samsung Flow mobile application prior to 4.8.03.5 allows Samsung Flow PC application connected with user device to access part of notification data in Secure Folder without authorization.
References
Link | Resource |
---|---|
https://security.samsungmobile.com/serviceWeb.smsb?year=2021&month=11 | Vendor Advisory |
Configurations
History
14 Jul 2022, 17:52
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-Other |
09 Nov 2021, 15:54
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-863 | |
CVSS |
v2 : v3 : |
v2 : 2.7
v3 : 5.7 |
References | (MISC) https://security.samsungmobile.com/serviceWeb.smsb?year=2021&month=11 - Vendor Advisory | |
CPE | cpe:2.3:a:samsung:samsung_flow:*:*:*:*:*:android:*:* |
05 Nov 2021, 03:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-11-05 03:15
Updated : 2024-02-04 22:08
NVD link : CVE-2021-25507
Mitre link : CVE-2021-25507
CVE.ORG link : CVE-2021-25507
JSON object : View
Products Affected
samsung
- samsung_flow
CWE