CVE-2021-25507

Severity
5.7MEDIUM
EPSS
0.1%
top 76.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 5
Latest updateMay 24

Description

Improper authorization vulnerability in Samsung Flow mobile application prior to 4.8.03.5 allows Samsung Flow PC application connected with user device to access part of notification data in Secure Folder without authorization.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.1 | Impact: 3.6

Affected Packages2 packages

CVEListV5samsung_mobile/samsung_flow-4.8.03.5
NVDsamsung/samsung_flow< 4.8.03.5

🔴Vulnerability Details

2
GHSA
GHSA-58m9-xprw-8c77: Improper authorization vulnerability in Samsung Flow mobile application prior to 42022-05-24
CVEList
CVE-2021-25507: Improper authorization vulnerability in Samsung Flow mobile application prior to 42021-11-05
CVE-2021-25507 (MEDIUM CVSS 5.7) | Improper authorization vulnerabilit | cvebase.io