MEDIUM
CVE-2021-25369
CVSS
5.5
KEV
Description
An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.
Summary dbcve.org
The sec_log file in Samsung's kernel prior to SMR MAR-2021 Release 1 had improper access control permissions, allowing unprivileged userspace applications to read sensitive kernel information that should be restricted.
Mitigation
Apply the SMR MAR-2021 Release 1 firmware update or later to affected Samsung devices to remediate the improper access control on the sec_log file.
Weakness (CWE)
CWE-200
Information Exposure
EPSS Score
1.12%
Probability of exploitation in next 30 days
64.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.