HIGH · 8.8

CVE-2021-25424

Improper authentication vulnerability in Tizen bluetooth-frwk prior to Firmware update JUN-2021 Release allows bluetooth attacker to take over the user's bluetooth device without user awareness.

Vulnerability Description

Improper authentication vulnerability in Tizen bluetooth-frwk prior to Firmware update JUN-2021 Release allows bluetooth attacker to take over the user's bluetooth device without user awareness.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
SamsungGalaxy Watch Active 2 Firmware< 5.5
SamsungGalaxy Watch Active 2-
SamsungGalaxy Watch Active Firmware< 5.5
SamsungGalaxy Watch Active-
SamsungGalaxy Watch Firmware< 5.5
SamsungGalaxy Watch-
SamsungGalaxy Watch 3 Firmware< 5.5
SamsungGalaxy Watch 3-
SamsungGear S3 Firmware< 5.5
SamsungGear S3-
SamsungGear S2 Firmware< 5.5
SamsungGear S2-
SamsungGear S Firmware< 5.5
SamsungGear S-
SamsungGear 2 Firmware< 5.5
SamsungGear 2-
SamsungGear 2 Neo Firmware< 5.5
SamsungGear 2 Neo-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-25424?

CVE-2021-25424 is a vulnerability with a CVSS score of 8.8 (HIGH). Improper authentication vulnerability in Tizen bluetooth-frwk prior to Firmware update JUN-2021 Release allows bluetooth attacker to take over the user's bluetooth device without user awareness.

How severe is CVE-2021-25424?

CVE-2021-25424 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-25424?

Check the references section above for vendor advisories and patch information. Affected products include: Samsung Galaxy Watch Active 2 Firmware, Samsung Galaxy Watch Active 2, Samsung Galaxy Watch Active Firmware, Samsung Galaxy Watch Active, Samsung Galaxy Watch Firmware.