CVE-2021-25406: Medium severity samsung gear s vulnerability
Published Jun 11, 2021
·Updated
Information exposure vulnerability in Gear S Plugin prior to version 2.2.05.20122441 allows unstrusted applications to access connected BT device information.
Affected Software
1 affected component
Samsung Gear S Android<2.2.05.20122441
Event History
Jun 11, 2021
CVE Published
via MITRE·02:45 PM
Data Sourced
via MITRE·02:45 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-25406?
CVE-2021-25406 is an information exposure vulnerability in Gear S Plugin.
2
What is the severity of CVE-2021-25406?
The severity of CVE-2021-25406 is medium with a CVSS score of 6.5.
3
How does CVE-2021-25406 affect Samsung Gear S?
CVE-2021-25406 affects Samsung Gear S devices running versions up to 2.2.05.20122441 of Gear S Plugin.
4
How can untrusted applications exploit CVE-2021-25406?
Untrusted applications can exploit CVE-2021-25406 to access connected BT device information on affected Samsung Gear S devices.
5
How can I fix CVE-2021-25406?
To fix CVE-2021-25406, users should update Gear S Plugin to version 2.2.05.20122441 or later.