CVE-2021-25420: Medium severity samsung galaxy watch plugin vulnerability
Published Jun 11, 2021
·Updated
Improper log management vulnerability in Galaxy Watch PlugIn prior to version 2.2.05.21033151 allows attacker with log permissions to leak Wi-Fi password connected to the user smartphone within log.
Affected Software
1 affected component
Samsung Galaxy Watch Plugin Android<2.2.05.21033151
Event History
Jun 11, 2021
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-25420?
CVE-2021-25420 has been classified as a high-severity vulnerability due to its potential to expose sensitive Wi-Fi credentials.
2
How do I fix CVE-2021-25420?
To mitigate CVE-2021-25420, update the Galaxy Watch Plugin to version 2.2.05.21033151 or later.
3
Who is affected by CVE-2021-25420?
CVE-2021-25420 affects users of the Galaxy Watch Plugin on Android devices prior to version 2.2.05.21033151.
4
What kind of data can be leaked due to CVE-2021-25420?
CVE-2021-25420 allows attackers with log access to leak the Wi-Fi password of the connected smartphone.
5
Is there a workaround for CVE-2021-25420?
The only effective workaround for CVE-2021-25420 is to upgrade to the patched version of the Galaxy Watch Plugin.