CVE-2021-25333

LOW

Samsung Pay <4.0.14 - Info Disclosure

Title source: llm
STIX 2.1

Description

Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance information over the lockscreen via scanning specific QR code.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://security.samsungmobile.com
Vendor Advisory x_refsource_confirm
https://security.samsungmobile.com/serviceWeb.smsb

Scores

CVSS v3 3.2
EPSS 0.0006
EPSS Percentile 19.8%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L

Details

CWE
CWE-200
Status published
Products (1)
samsung/pay_mini < 4.0.14
Published Mar 04, 2021
Tracked Since Feb 18, 2026