Improper Export Vulnerability in Samsung Pay
CVE-2021-25527

3.8LOW

Key Information:

Vendor
Samsung
Vendor
CVE Published:
8 December 2021

Summary

An improper export vulnerability in Samsung Pay, specifically for users in India, allows unauthorized access to the Bill Pay and Recharge menu. This flaw exists in versions prior to 4.1.77, creating a risk where an attacker can exploit this weakness to perform actions without the necessary authentication, leading to potential financial and personal data exposure.

Affected Version(s)

Samsung Pay - < 4.1.77

References

CVSS V3.1

Score:
3.8
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.