MEDIUM

CVE-2021-25369

Samsung Android 2021-03-26 CVSS v3.1
CVSS
5.5
KEV

Description

An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.

Summary dbcve.org

The sec_log file in Samsung's kernel prior to SMR MAR-2021 Release 1 had improper access control permissions, allowing unprivileged userspace applications to read sensitive kernel information that should be restricted.

Mitigation

Apply the SMR MAR-2021 Release 1 firmware update or later to affected Samsung devices to remediate the improper access control on the sec_log file.

Weakness (CWE)

CWE-200 Information Exposure

EPSS Score

1.12%
Probability of exploitation in next 30 days
64.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE