CVE-2021-25335Improper Check or Handling of Exceptional Conditions in Mobile Devices

Severity
2.5LOWNVD
EPSS
0.0%
top 86.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 4
Latest updateMay 24

Description

Improper lockscreen status check in cocktailbar service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows unauthenticated users to access hidden notification contents over the lockscreen in specific condition.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 1.0 | Impact: 1.4

Affected Packages3 packages

CVEListV5samsung_mobile/samsung_mobile_devicesSelected Q(10.0)SMR Mar-2021 Release 1
NVDgoogle/android10.0

🔴Vulnerability Details

2
GHSA
GHSA-5wx9-g7j9-7cvc: Improper lockscreen status check in cocktailbar service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows unauthenticated users to acce2022-05-24
CVEList
CVE-2021-25335: Improper lockscreen status check in cocktailbar service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows unauthenticated users to acce2021-03-04
CVE-2021-25335 — Samsung Mobile Devices vulnerability | cvebase