CVE-2021-25331: Infoleak
Published Mar 4, 2021
·Updated
Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance information over the lockscreen in specific condition.
Affected Software
1 affected component
Samsung Pay mini<4.0.14
Event History
Mar 4, 2021
CVE Published
via MITRE·08:55 PM
Data Sourced
via MITRE·08:55 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-25331?
The severity of CVE-2021-25331 is classified as medium due to the potential unauthorized access to sensitive balance information.
2
How do I fix CVE-2021-25331?
To fix CVE-2021-25331, update the Samsung Pay mini application to version 4.0.14 or later.
3
What types of information are exposed by CVE-2021-25331?
CVE-2021-25331 exposes unauthorized access to balance information during certain conditions over the lockscreen.
4
Which versions of Samsung Pay mini are affected by CVE-2021-25331?
CVE-2021-25331 affects all versions of Samsung Pay mini prior to v4.0.14.
5
Is authentication bypass a concern in CVE-2021-25331?
Yes, CVE-2021-25331 involves improper access control which constitutes an authentication bypass vulnerability.