First published: Fri Nov 05 2021(Updated: )
Improper authentication in Samsung Pass prior to 3.0.02.4 allows to use app without authentication when lockscreen is unlocked.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Samsung Pass | <3.0.02.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25505 is categorized as a high-severity vulnerability due to improper authentication in Samsung Pass.
To fix CVE-2021-25505, users should update Samsung Pass to version 3.0.02.4 or later.
CVE-2021-25505 affects Samsung Pass versions prior to 3.0.02.4 on Android devices.
CVE-2021-25505 cannot be exploited remotely as it requires local access to the device when the lockscreen is unlocked.
CVE-2021-25505 allows the use of the Samsung Pass app without authentication, undermining user security when the device is unlocked.