CVE-2021-25374

Severity
7.5HIGH
EPSS
7.6%
top 8.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 9
Latest updateMay 24

Description

An improper authorization vulnerability in Samsung Members "samsungrewards" scheme for deeplink in versions 2.4.83.9 in Android O(8.1) and below, and 3.9.00.9 in Android P(9.0) and above allows remote attackers to access a user data related with Samsung Account.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:NExploitability: 3.9 | Impact: 4.0

Affected Packages2 packages

CVEListV5samsung_mobile/samsung_membersAndroid O(8.x) and below2.4.83.9+1
NVDsamsung/members2.4.83.9+1

🔴Vulnerability Details

2
GHSA
GHSA-m8xj-8969-xvhx: An improper authorization vulnerability in Samsung Members "samsungrewards" scheme for deeplink in versions 22022-05-24
CVEList
CVE-2021-25374: An improper authorization vulnerability in Samsung Members "samsungrewards" scheme for deeplink in versions 22021-04-09