⚠ Actively exploited
Added to CISA KEV on 2023-06-29. Federal agencies required to patch by 2023-07-20. Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

CVE-2021-25395Race Condition in Mobile Devices

CWE-362Race Condition5 documents5 sources
Severity
6.4MEDIUMNVD
EPSS
0.2%
top 62.81%
CISA KEV
KEV
Added 2023-06-29
Due 2023-07-20
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedJun 11
KEV addedJun 29
KEV dueJul 20
CISA Required Action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable

Description

A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is compromised.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.5 | Impact: 5.9

Affected Packages2 packages

CVEListV5samsung_mobile/samsung_mobile_devicesO(8.x), P(9.0), Q(10.0), R(11.0)SMR MAY-2021 Release 1
NVDsamsung/android4 versions+3

🔴Vulnerability Details

3
GHSA
GHSA-fj4w-55pf-m8j9: A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is com2022-05-24
CVEList
CVE-2021-25395: A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is com2021-06-11
VulnCheck
Samsung Mobile Devices Race Condition Vulnerability2021

📋Vendor Advisories

1
CISA
Samsung Mobile Devices Race Condition Vulnerability2023-06-29
CVE-2021-25395 — Race Condition in Mobile Devices | cvebase