7.8

CVE-2021-25381

Using unsafe PendingIntent in Samsung Account in versions 10.8.0.4 in Android P(9.0) and below, and 12.1.1.3 in Android Q(10.0) and above allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.

Data is provided by the National Vulnerability Database (NVD)
SamsungAccount Version10.8.0.4
   GoogleAndroid Version1.0
   GoogleAndroid Version1.1
   GoogleAndroid Version1.5
   GoogleAndroid Version1.6
   GoogleAndroid Version2.0
   GoogleAndroid Version2.0.1
   GoogleAndroid Version2.1
   GoogleAndroid Version2.2
   GoogleAndroid Version2.2 Updaterev1
   GoogleAndroid Version2.2.1
   GoogleAndroid Version2.2.2
   GoogleAndroid Version2.2.3
   GoogleAndroid Version2.3
   GoogleAndroid Version2.3 Updaterev1
   GoogleAndroid Version2.3.1
   GoogleAndroid Version2.3.2
   GoogleAndroid Version2.3.3
   GoogleAndroid Version2.3.4
   GoogleAndroid Version2.3.5
   GoogleAndroid Version2.3.6
   GoogleAndroid Version2.3.7
   GoogleAndroid Version3.0
   GoogleAndroid Version3.1
   GoogleAndroid Version3.2
   GoogleAndroid Version3.2.1
   GoogleAndroid Version3.2.2
   GoogleAndroid Version3.2.4
   GoogleAndroid Version3.2.6
   GoogleAndroid Version4.0
   GoogleAndroid Version4.0.1
   GoogleAndroid Version4.0.2
   GoogleAndroid Version4.0.3
   GoogleAndroid Version4.0.4
   GoogleAndroid Version4.1
   GoogleAndroid Version4.1.1
   GoogleAndroid Version4.1.2
   GoogleAndroid Version4.2
   GoogleAndroid Version4.2.1
   GoogleAndroid Version4.2.2
   GoogleAndroid Version4.3
   GoogleAndroid Version4.3.1
   GoogleAndroid Version4.4
   GoogleAndroid Version4.4.1
   GoogleAndroid Version4.4.2
   GoogleAndroid Version4.4.3
   GoogleAndroid Version4.4.4
   GoogleAndroid Version5.0
   GoogleAndroid Version5.0.1
   GoogleAndroid Version5.0.2
   GoogleAndroid Version5.1
   GoogleAndroid Version5.1.0
   GoogleAndroid Version5.1.1
   GoogleAndroid Version6.0
   GoogleAndroid Version6.0.1
   GoogleAndroid Version7.0
   GoogleAndroid Version7.1.0
   GoogleAndroid Version7.1.1
   GoogleAndroid Version7.1.2
   GoogleAndroid Version8.0
   GoogleAndroid Version8.1
   GoogleAndroid Version9.0
SamsungAccount Version12.1.1.3
   GoogleAndroid Version10.0
   GoogleAndroid Version11.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.076
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
mobile.security@samsung.com 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

CWE-285 Improper Authorization

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.