Improper Access Control in Samsung KnoxGuard Affects Security Functionality
CVE-2025-21047

5.2MEDIUM

Key Information:

Vendor

Samsung

Vendor
CVE Published:
10 October 2025

What is CVE-2025-21047?

An improper access control vulnerability in Samsung KnoxGuard allows physical attackers to exploit privileged APIs. This weakness can lead to unauthorized access and manipulation of security features within the device management framework. Users are encouraged to update their KnoxGuard to the latest version released in October 2025 to mitigate potential risks associated with this vulnerability.

Affected Version(s)

Samsung Mobile Devices SMR Oct-2025 Release in Android 14, 15, 16

References

CVSS V3.1

Score:
5.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-21047 : Improper Access Control in Samsung KnoxGuard Affects Security Functionality