First published: Fri Apr 09 2021(Updated: )
An improper synchronization logic in Samsung Email prior to version 6.1.41.0 can leak messages in certain mailbox in plain text when STARTTLS negotiation is failed.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Email | <6.1.41.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25376 is a vulnerability in Samsung Email prior to version 6.1.41.0 that can leak messages in certain mailbox in plain text when STARTTLS negotiation fails.
CVE-2021-25376 has a severity level of medium, with a CVSS score of 5.3.
If you are using Samsung Email prior to version 6.1.41.0, this vulnerability could lead to the leakage of messages in certain mailboxes in plain text when STARTTLS negotiation fails.
To fix CVE-2021-25376, you need to update Samsung Email to version 6.1.41.0 or later.
You can find more information about CVE-2021-25376 on the Samsung Mobile Security website.