CVE-2025-20996: Medium severity samsung smart switch vulnerability
Published Jun 4, 2025
·Updated
Improper authorization in Smart Switch installed on non-Samsung Device prior to version 3.7.64.10 allows local attackers to read data with the privilege of Smart Switch. User interaction is required for triggering this vulnerability.
Affected Software
2 affected components
Samsung Smart Switch<3.7.64.10
Samsung Smart Switch<3.7.64.10
Event History
Jun 4, 2025
CVE Published
via MITRE·04:56 AM
Data Sourced
via MITRE·04:56 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-20996?
CVE-2025-20996 has a moderate severity level due to improper authorization allowing local attackers to access sensitive data.
2
How do I fix CVE-2025-20996?
To fix CVE-2025-20996, update the Smart Switch application to version 3.7.64.10 or later.
3
Who is affected by CVE-2025-20996?
CVE-2025-20996 affects users of Smart Switch installed on non-Samsung devices prior to version 3.7.64.10.
4
What type of attacks can CVE-2025-20996 allow?
CVE-2025-20996 allows local attackers to read sensitive data with the privileges of the Smart Switch application.
5
Is user interaction required to exploit CVE-2025-20996?
Yes, user interaction is required to trigger the CVE-2025-20996 vulnerability.