Improper MDM Policy Management in Samsung's Knox Manage
CVE-2021-25442
7.5HIGH
Summary
The KME module in Samsung's Knox Manage prior to version 1.39 contains an improper MDM policy management vulnerability that allows MDM users to bypass authentication mechanisms. This flaw can potentially lead to unauthorized access, enabling attackers to manipulate device management settings without proper verification.
Affected Version(s)
Knox Mobile Enrollment -
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved