Vulnerability Description
An issue was discovered on Samsung mobile devices with Q(10.0) (with ONEUI 2.1) software. In the Lockscreen state, the Quick Share feature allows unauthenticated downloads, aka file injection. The Samsung ID is SVE-2020-17760 (August 2020).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Android | 10.0 |
Related Weaknesses (CWE)
References
- https://security.samsungmobile.com/securityUpdate.smsbVendor Advisory
- https://security.samsungmobile.com/securityUpdate.smsbVendor Advisory
FAQ
What is CVE-2020-25048?
CVE-2020-25048 is a vulnerability with a CVSS score of 4.6 (MEDIUM). An issue was discovered on Samsung mobile devices with Q(10.0) (with ONEUI 2.1) software. In the Lockscreen state, the Quick Share feature allows unauthenticated downloads, aka file injection. The Sam...
How severe is CVE-2020-25048?
CVE-2020-25048 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-25048?
Check the references section above for vendor advisories and patch information. Affected products include: Google Android.