First published: Thu Aug 05 2021(Updated: )
Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause local file inclusion in webview.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
SmartThings | <1.7.67.25 | |
SmartThings |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25447 is classified as a medium severity vulnerability due to its impact on improper access control.
To remediate CVE-2021-25447, upgrade the SmartThings application to version 1.7.67.25 or later.
CVE-2021-25447 is an improper access control vulnerability that allows untrusted applications to cause local file inclusion in webview.
SmartThings versions prior to 1.7.67.25 are affected by CVE-2021-25447.
CVE-2021-25447 requires local execution and cannot be exploited remotely.