CVE-2021-25343

Severity
3.3LOW
EPSS
0.1%
top 83.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 4
Latest updateMay 24

Description

Calling of non-existent provider in Samsung Members prior to version 2.4.81.13 (in Android O(8.1) and below) and 3.8.00.13 (in Android P(9.0) and above) allows unauthorized actions including denial of service attack by hijacking the provider.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 2.5 | Impact: 1.4

Affected Packages2 packages

NVDsamsung/members< 2.4.81.13+1
CVEListV5samsung_mobile/samsung_membersAndroid O(8.1) and below2.4.81.13+1

🔴Vulnerability Details

2
GHSA
GHSA-8mqf-hqpq-qxwj: Calling of non-existent provider in Samsung Members prior to version 22022-05-24
CVEList
CVE-2021-25343: Calling of non-existent provider in Samsung Members prior to version 22021-03-04