CVE-2021-25437: Input Validation
Published Jul 8, 2021
·Updated
Improper access control vulnerability in Tizen FOTA service prior to Firmware update JUL-2021 Release allows attackers to arbitrary code execution by replacing FOTA update file.
Affected Software
1 affected component
Linux Tizen<5.5
Event History
Jul 8, 2021
CVE Published
via MITRE·01:47 PM
Data Sourced
via MITRE·01:47 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-25437?
CVE-2021-25437 is an improper access control vulnerability in Tizen FOTA service prior to the Firmware update JUL-2021 Release.
2
How does CVE-2021-25437 affect Tizen FOTA service?
CVE-2021-25437 allows attackers to execute arbitrary code by replacing the FOTA update file.
3
What is the severity of CVE-2021-25437?
CVE-2021-25437 has a severity rating of 9.8 (Critical).
4
What software versions are affected by CVE-2021-25437?
The vulnerability affects Tizen FOTA service versions up to and exclusive of 5.5.
5
How can I fix CVE-2021-25437?
To fix CVE-2021-25437, it is recommended to update to the JUL-2021 Release of the Tizen Firmware.