PT-2021-16597 · Samsung · Gear S Plugin
Dawn Security Lab
·
Published
2021-06-11
·
Updated
2021-06-17
·
CVE-2021-25406
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Gear S Plugin versions prior to 2.2.05.20122441
Description:
The issue allows untrusted applications to access information about connected Bluetooth devices.
Recommendations:
For versions prior to 2.2.05.20122441, update to version 2.2.05.20122441 or later to resolve the issue.
Fix
Incorrect Authorization
Insecure Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gear S Plugin