First published: Fri Jun 11 2021(Updated: )
Improper log management vulnerability in Watch Active PlugIn prior to version 2.2.07.21033151 allows attacker with log permissions to leak Wi-Fi password connected to the user smartphone within log.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Watch Active Plugin | <2.2.07.21033151 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25422 is classified as a moderate severity vulnerability.
To mitigate CVE-2021-25422, upgrade the Watch Active PlugIn to version 2.2.07.21033151 or later.
Users of the Samsung Watch Active PlugIn prior to version 2.2.07.21033151 are affected by CVE-2021-25422.
CVE-2021-25422 is an improper log management vulnerability that can allow password leakage.
Yes, an attacker with log permissions can exploit CVE-2021-25422 remotely.