Improper access control in Samsung Mobile Firmware - CVE-2021-25369

 

Improper access control in Samsung Mobile Firmware - CVE-2021-25369

Published: November 10, 2022


Vulnerability identifier: #VU69231
CSH Severity: Medium
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-25369
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper access restrictions to the sec_log file. A local application can read the log file and obtain sensitive system information.

Note, the vulnerability is being actively exploited in the wild.


Affected software

Samsung Mobile Firmware

How to mitigate CVE-2021-25369

Install updates from vendor's website.

Samsung Mobile Firmware - update to SMR-MAR-2021

External References

Related Security Bulletins