CVE-2021-25351

LOW

Samsung Account <10.7.0.7, <12.1.1.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

Improper Access Control in EmailValidationView in Samsung Account prior to version 10.7.0.7 and 12.1.1.3 allows physically proximate attackers to log out user account on device without user password.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://security.samsungmobile.com/
Vendor Advisory x_refsource_misc
https://security.samsungmobile.com/serviceWeb.smsb

Scores

CVSS v3 3.2
EPSS 0.0005
EPSS Percentile 15.2%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L

Details

CWE
CWE-285
Status published
Products (1)
samsung/account < 10.7.07
Published Mar 25, 2021
Tracked Since Feb 18, 2026