CVE-2025-20984: Medium severity Samsung Samsung Cloud for Galaxy Watch vulnerability
Published Jun 4, 2025
·Updated
Incorrect default permission in Samsung Cloud for Galaxy Watch prior to SMR Jun-2025 Release 1 allows local attackers to access data in Samsung Cloud for Galaxy Watch.
Affected Software
12 affected components
Samsung Samsung Cloud for Galaxy Watch<SMR Jun-2025 Release 1
All of the following
Samsung Wear Os=5.0
Any of the following
Samsung Galaxy Watch
Samsung Galaxy Watch 4
Samsung Galaxy Watch 4 Classic
Samsung Galaxy Watch 5
Samsung Galaxy Watch 5 Pro
Samsung Galaxy Watch 6
Samsung Galaxy Watch 6 Classic
Samsung Galaxy Watch 7
Samsung Galaxy Watch Fe
Samsung Galaxy Watch Ultra
Event History
Jun 4, 2025
CVE Published
via MITRE·04:56 AM
Data Sourced
via MITRE·04:56 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-20984?
CVE-2025-20984 is classified with a medium severity due to potential local attacks on data access.
2
How do I fix CVE-2025-20984?
To fix CVE-2025-20984, update Samsung Cloud for Galaxy Watch to the SMR Jun-2025 Release 1 version or later.
3
Who is affected by CVE-2025-20984?
Users of Samsung Cloud for Galaxy Watch prior to SMR Jun-2025 Release 1 are affected by CVE-2025-20984.
4
What kind of data can be accessed due to CVE-2025-20984?
CVE-2025-20984 allows local attackers to access sensitive data stored in the Samsung Cloud for Galaxy Watch.
5
Is there a workaround for CVE-2025-20984?
There is no official workaround for CVE-2025-20984; updating to the latest version is recommended.