PT-2021-16565 · Samsung · Samsung Members

Published

2021-04-09

·

Updated

2022-07-14

·

CVE-2021-25374

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Samsung Members versions 2.4.83.9 and 3.9.00.9
Description: The issue is related to an improper authorization vulnerability in the "samsungrewards" scheme for deeplink, allowing remote attackers to access user data related to Samsung Account. This affects devices running Android O(8.1) and below, as well as Android P(9.0) and above.
Recommendations: For version 2.4.83.9, update to a version that addresses the improper authorization issue. For version 3.9.00.9, update to a version that addresses the improper authorization issue.

Exploit

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-25374

Affected Products

Samsung Members