Improper Privilege Management in SmartThings by Samsung
CVE-2021-25508
5.3MEDIUM
What is CVE-2021-25508?
The identified vulnerability in SmartThings prior to version 1.7.73.22 pertains to improper privilege management associated with the API Key. This flaw permits potential attackers to misuse the API key without any restrictions, leading to unauthorized access and manipulation of the system. Safeguarding against this vulnerability is crucial to maintain the integrity and security of user accounts and connected devices.
Affected Version(s)
SmartThings - < 1.7.73.22