CVE-2021-25351

I

mproper Access Control in EmailValidationView in Samsung Account prior to version 10.7.0.7 and 12.1.1.3 allows physically proximate attackers to log out user account on device without user password.

Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:samsung:account:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:9.0:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:samsung:account:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:*

History

21 Nov 2024, 05:54

Type Values Removed Values Added
References () https://security.samsungmobile.com/ - Vendor Advisory () https://security.samsungmobile.com/ - Vendor Advisory
References () https://security.samsungmobile.com/serviceWeb.smsb - Vendor Advisory () https://security.samsungmobile.com/serviceWeb.smsb - Vendor Advisory
CVSS v2 : 2.1
v3 : 2.4
v2 : 2.1
v3 : 3.2

Information

Published : 2021-03-25 17:15

Updated : 2024-11-21 05:54


NVD link : CVE-2021-25351

Mitre link : CVE-2021-25351

CVE.ORG link : CVE-2021-25351


JSON object : View

Products Affected
CWE
CWE-285

Improper Authorization

NVD-CWE-Other