Information Exposure in Galaxy Watch Plugin by Samsung
CVE-2022-25827

1.9LOW

Key Information:

Vendor
Samsung
Vendor
CVE Published:
10 March 2022

Summary

The Galaxy Watch Plugin from Samsung contains a vulnerability that allows attackers to gain unauthorized access to sensitive WiFi password information. This exposure occurs through the logging mechanism of the plugin, which fails to adequately protect stored credentials, putting users at risk of unauthorized access to their connected networks. It is crucial for users to update to version 2.2.05.22012751 or later to mitigate potential security threats associated with this flaw.

Affected Version(s)

Galaxy Watch PlugIn - < 2.2.05.22012751

References

CVSS V3.1

Score:
1.9
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.