Information Exposure Vulnerability in SmartThings by Samsung
CVE-2021-25404

3.3LOW

Key Information:

Vendor
Samsung
Vendor
CVE Published:
11 June 2021

Summary

An information exposure vulnerability in SmartThings allows unauthorized users to access sensitive user information through system logs. This flaw affects versions prior to 1.7.64.21, making it crucial for users to update their applications to safeguard their data.

Affected Version(s)

SmartThings < 1.7.64.21

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.