Lucene search

K
cveSamsung MobileCVE-2021-25437
HistoryJul 08, 2021 - 2:15 p.m.

CVE-2021-25437

2021-07-0814:15:08
CWE-20
Samsung Mobile
web.nvd.nist.gov
37
2
cve-2021-25437
tizen fota
access control vulnerability
arbitrary code execution
file replacement

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.5

Confidence

High

EPSS

0.005

Percentile

76.0%

Improper access control vulnerability in Tizen FOTA service prior to Firmware update JUL-2021 Release allows attackers to arbitrary code execution by replacing FOTA update file.

Affected configurations

Nvd
Node
linuxtizenRange<5.5
VendorProductVersionCPE
linuxtizen*cpe:2.3:o:linux:tizen:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Tizen wearable devices",
    "vendor": "Samsung Mobile",
    "versions": [
      {
        "lessThan": "Firmware update JUL-2021 Release",
        "status": "affected",
        "version": "Tizen 5.5",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.5

Confidence

High

EPSS

0.005

Percentile

76.0%

Related for CVE-2021-25437