CVE-2021-25376

LOW

Samsung Email <6.1.41.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

An improper synchronization logic in Samsung Email prior to version 6.1.41.0 can leak messages in certain mailbox in plain text when STARTTLS negotiation is failed.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
https://security.samsungmobile.com/
Vendor Advisory x_refsource_confirm
https://security.samsungmobile.com/serviceWeb.smsb

Scores

CVSS v3 3.1
EPSS 0.0079
EPSS Percentile 52.5%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200 CWE-662
Status published
Products (1)
samsung/email < 6.1.41.0
Published Apr 09, 2021
Tracked Since Feb 18, 2026