First published: Fri Jun 11 2021(Updated: )
Improper log management vulnerability in Galaxy Watch PlugIn prior to version 2.2.05.21033151 allows attacker with log permissions to leak Wi-Fi password connected to the user smartphone within log.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Galaxy Watch Plugin | <2.2.05.21033151 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25420 has been classified as a high-severity vulnerability due to its potential to expose sensitive Wi-Fi credentials.
To mitigate CVE-2021-25420, update the Galaxy Watch Plugin to version 2.2.05.21033151 or later.
CVE-2021-25420 affects users of the Galaxy Watch Plugin on Android devices prior to version 2.2.05.21033151.
CVE-2021-25420 allows attackers with log access to leak the Wi-Fi password of the connected smartphone.
The only effective workaround for CVE-2021-25420 is to upgrade to the patched version of the Galaxy Watch Plugin.