CVE-2021-25525: Medium severity samsung pay vulnerability
Published Dec 8, 2021
·Updated
Improper check or handling of exception conditions vulnerability in Samsung Pay (US only) prior to version 4.0.65 allows attacker to use NFC without user recognition.
Affected Software
1 affected component
Samsung Pay<4.0.65
Event History
Dec 8, 2021
CVE Published
via MITRE·02:20 PM
Data Sourced
via MITRE·02:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-25525?
CVE-2021-25525 is classified as a high severity vulnerability due to the potential for unauthorized NFC transactions.
2
How do I fix CVE-2021-25525?
To fix CVE-2021-25525, update your Samsung Pay application to version 4.0.65 or later.
3
What does CVE-2021-25525 affect?
CVE-2021-25525 affects the Samsung Pay application on devices running versions prior to 4.0.65.
4
Can CVE-2021-25525 lead to data theft?
Yes, CVE-2021-25525 may allow attackers to initiate NFC transactions without user consent, potentially leading to unauthorized access to funds.
5
Is CVE-2021-25525 specific to certain countries?
Yes, CVE-2021-25525 specifically affects Samsung Pay in the United States.