3.6
CVE-2021-25366
- EPSS 0.07%
- Published 25.03.2021 17:15:13
- Last modified 21.11.2024 05:54:50
- Source mobile.security@samsung.com
- Teams watchlist Login
- Open Login
Improper access control in Samsung Internet prior to version 13.2.1.70 allows physically proximate attackers to bypass the secret mode's authentication.
Data is provided by the National Vulnerability Database (NVD)
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.07% | 0.182 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 2.9 | 0.3 | 2.5 |
CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
|
nvd@nist.gov | 3.6 | 3.9 | 4.9 |
AV:L/AC:L/Au:N/C:P/I:P/A:N
|
mobile.security@samsung.com | 3.2 | 0.2 | 2.7 |
CVSS:3.1/AV:P/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N
|
CWE-703 Improper Check or Handling of Exceptional Conditions
The product does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the product.