CVE-2021-25403
Published Jun 11, 2021
Last updated 2 years ago
Overview
- Description
- Intent redirection vulnerability in Samsung Account prior to version 10.8.0.4 in Android P(9.0) and below, and 12.2.0.9 in Android Q(10.0) and above allows attacker to access contacts and file provider using SettingWebView component.
- Source
- mobile.security@samsung.com
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 3.3
- Impact score
- 1.4
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Severity
- LOW
CVSS 2.0
- Type
- Primary
- Base score
- 2.1
- Impact score
- 2.9
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
- mobile.security@samsung.com
- CWE-200
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:samsung:account:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AD83F712-2186-4AE5-9D43-7216235D6A19", "versionEndExcluding": "10.8.0.4" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:google:android:*:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "C8B27FBB-7C86-4328-86CF-FA6D48EECFAE", "versionEndIncluding": "9.0" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:samsung:account:12.2.0.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9C84CDBB-C7EE-4C92-93A7-D31D2C6B9A31" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:google:android:*:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "1F050AF1-DEAC-4BDB-9F7F-C940C02A4B92", "versionStartIncluding": "10.0" } ], "operator": "OR" } ], "operator": "AND" } ]