CVE-2021-25376

LOW

Samsung Email <6.1.41.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

An improper synchronization logic in Samsung Email prior to version 6.1.41.0 can leak messages in certain mailbox in plain text when STARTTLS negotiation is failed.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
https://security.samsungmobile.com/
Vendor Advisory x_refsource_confirm
https://security.samsungmobile.com/serviceWeb.smsb

Scores

CVSS v3 3.1
EPSS 0.0079
EPSS Percentile 51.1%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-662 CWE-200
Status published
Products (1)
samsung/email < 6.1.41.0
Published Apr 09, 2021
Tracked Since Feb 18, 2026