PT-2021-16565 · Samsung · Samsung Members
Published
2021-04-09
·
Updated
2022-07-14
·
CVE-2021-25374
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Samsung Members versions 2.4.83.9 and 3.9.00.9
Description:
The issue is related to an improper authorization vulnerability in the "samsungrewards" scheme for deeplink, allowing remote attackers to access user data related to Samsung Account. This affects devices running Android O(8.1) and below, as well as Android P(9.0) and above.
Recommendations:
For version 2.4.83.9, update to a version that addresses the improper authorization issue.
For version 3.9.00.9, update to a version that addresses the improper authorization issue.
Exploit
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Samsung Members