CVE-2021-25332: Infoleak
Published Mar 4, 2021
·Updated
Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to contacts information over the lockscreen in specific condition.
Affected Software
1 affected component
Samsung Pay mini<4.0.14
Event History
Mar 4, 2021
CVE Published
via MITRE·08:55 PM
Data Sourced
via MITRE·08:55 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-25332?
CVE-2021-25332 has a medium severity level due to its improper access control allowing unauthorized access to contacts.
2
How do I fix CVE-2021-25332?
To fix CVE-2021-25332, update your Samsung Pay mini application to version 4.0.14 or later.
3
What impact does CVE-2021-25332 have on users?
CVE-2021-25332 can potentially expose users' contacts information when accessed over the lockscreen.
4
Which versions of Samsung Pay mini are affected by CVE-2021-25332?
CVE-2021-25332 affects all versions of Samsung Pay mini prior to v4.0.14.
5
Who is affected by CVE-2021-25332?
Users of Samsung Pay mini versions prior to 4.0.14 are vulnerable to CVE-2021-25332.