Vulnerability Description
Improper Access Control in EmailValidationView in Samsung Account prior to version 10.7.0.7 and 12.1.1.3 allows physically proximate attackers to log out user account on device without user password.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Samsung | Account | < 10.7.07 |
| Android | 9.0 |
Related Weaknesses (CWE)
References
- https://security.samsungmobile.com/Vendor Advisory
- https://security.samsungmobile.com/serviceWeb.smsbVendor Advisory
- https://security.samsungmobile.com/Vendor Advisory
- https://security.samsungmobile.com/serviceWeb.smsbVendor Advisory
FAQ
What is CVE-2021-25351?
CVE-2021-25351 is a vulnerability with a CVSS score of 3.2 (LOW). Improper Access Control in EmailValidationView in Samsung Account prior to version 10.7.0.7 and 12.1.1.3 allows physically proximate attackers to log out user account on device without user password.
How severe is CVE-2021-25351?
CVE-2021-25351 has been rated LOW with a CVSS base score of 3.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-25351?
Check the references section above for vendor advisories and patch information. Affected products include: Samsung Account, Google Android.