CVE-2021-25432 Vulnerability Details

  /     /     /  

CVE-2021-25432 Metadata Quick Info

CVE Published: 08/07/2021 | CVE Updated: 03/08/2024 | CVE Year: 2021
Source: Samsung Mobile | Vendor: Samsung Mobile | Product: Samsung Members
Status : PUBLISHED

CVE-2021-25432 Description

Information exposure vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to access chat data.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-200
CWE Name: CWE-200 Information Exposure
Source: Samsung Mobile

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).