CVE-2021-25421: Medium severity samsung galaxy watch 3 plugin vulnerability
Published Jun 11, 2021
·Updated
Improper log management vulnerability in Galaxy Watch3 PlugIn prior to version 2.2.09.21033151 allows attacker with log permissions to leak Wi-Fi password connected to the user smartphone within log.
Affected Software
1 affected component
Samsung Galaxy Watch 3 Plugin Android<2.2.09.21033151
Event History
Jun 11, 2021
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-25421?
CVE-2021-25421 is rated as a moderate severity vulnerability due to its potential to expose sensitive Wi-Fi credentials.
2
How do I fix CVE-2021-25421?
To fix CVE-2021-25421, update the Galaxy Watch3 PlugIn to version 2.2.09.21033151 or later.
3
Who is affected by CVE-2021-25421?
CVE-2021-25421 affects users of the Samsung Galaxy Watch3 PlugIn prior to version 2.2.09.21033151.
4
What type of vulnerability is CVE-2021-25421?
CVE-2021-25421 is an improper log management vulnerability that can lead to the leakage of Wi-Fi passwords.
5
Can unauthorized users exploit CVE-2021-25421?
Yes, attackers with log permissions can exploit CVE-2021-25421 to access sensitive information such as Wi-Fi passwords.