CVE Published: 09/04/2021 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: Samsung Mobile |
Vendor: Samsung Mobile |
Product: Samsung Members Status : PUBLISHED
CVE-2021-25374 Description
An improper authorization vulnerability in Samsung Members "samsungrewards" scheme for deeplink in versions 2.4.83.9 in Android O(8.1) and below, and 3.9.00.9 in Android P(9.0) and above allows remote attackers to access a user data related with Samsung Account.
Metrics
CVSS Version: 3.1 |
Base Score: 8.6 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N