PT-2020-6819 · Google+1 · Android+1

Published

2020-12-10

·

Updated

2025-10-30

·

CVE-2021-25369

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Samsung Mobile Devices versions prior to SMR MAR-2021 Release 1
Description The issue is related to an improper access control vulnerability in the sec log file, which exposes sensitive kernel information to userspace. This vulnerability is associated with insufficient access control in the sec log file, located at /data/log/sec log.log, in Samsung mobile devices running Android. The exploitation of this vulnerability could allow an attacker to gain unauthorized access to protected information.
Recommendations For versions prior to SMR MAR-2021 Release 1, update to SMR MAR-2021 Release 1 or later to resolve the issue. As a temporary workaround, consider restricting access to the sec log file to minimize the risk of exploitation.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2022-07368
CVE-2021-25369

Affected Products

Android
Samsung Mobile Devices