First published: Fri Jun 11 2021(Updated: )
Improper log management vulnerability in Galaxy Watch3 PlugIn prior to version 2.2.09.21033151 allows attacker with log permissions to leak Wi-Fi password connected to the user smartphone within log.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Galaxy Watch 3 Plugin | <2.2.09.21033151 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25421 is rated as a moderate severity vulnerability due to its potential to expose sensitive Wi-Fi credentials.
To fix CVE-2021-25421, update the Galaxy Watch3 PlugIn to version 2.2.09.21033151 or later.
CVE-2021-25421 affects users of the Samsung Galaxy Watch3 PlugIn prior to version 2.2.09.21033151.
CVE-2021-25421 is an improper log management vulnerability that can lead to the leakage of Wi-Fi passwords.
Yes, attackers with log permissions can exploit CVE-2021-25421 to access sensitive information such as Wi-Fi passwords.