CVE-2021-25424: High severity samsung galaxy watch active 2 firmware vulnerability
Published Jun 11, 2021
·Updated
Improper authentication vulnerability in Tizen bluetooth-frwk prior to Firmware update JUN-2021 Release allows bluetooth attacker to take over the user's bluetooth device without user awareness.
Affected Software
18 affected components
Samsung Galaxy Watch Active 2 Firmware<5.5
Samsung Galaxy Watch Active 2
Samsung Galaxy Watch Active Firmware<5.5
Samsung Galaxy Watch Active
Samsung Galaxy Watch Firmware<5.5
Samsung Galaxy Watch
Samsung Galaxy Watch 3 Firmware<5.5
Samsung Galaxy Watch 3
Samsung Gear S3 Firmware<5.5
Samsung Gear S3
Samsung Gear S2 Firmware<5.5
Samsung Gear S2
Samsung Gear S Firmware<5.5
Samsung Gear s
Samsung Gear 2 Firmware<5.5
Samsung Gear 2
Samsung Gear 2 Neo Firmware<5.5
Samsung Gear 2 Neo
Event History
Jun 11, 2021
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-25424.
2
What is the severity of CVE-2021-25424?
The severity of CVE-2021-25424 is high with a CVSS score of 8.8.
3
Which devices are affected by CVE-2021-25424?
Devices such as Samsung Galaxy Watch, Samsung Gear S3, Samsung Gear S2, and Samsung Gear 2 are affected by CVE-2021-25424.
4
How can an attacker exploit CVE-2021-25424?
An attacker can exploit CVE-2021-25424 by using a bluetooth attack to take over a user's bluetooth device without their awareness.
5
Is there a firmware update available to fix CVE-2021-25424?
Yes, a firmware update was released in June 2021 to fix CVE-2021-25424. It is recommended to update to the latest firmware version to mitigate this vulnerability.