---
cve: "CVE-2021-25374"
severity: "HIGH"
cvss: 8.6
epss: "3.1%"
vendor: "Samsung Mobile"
kev: false
exploited: false
published: "2021-04-09 17:38:29"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-11T12:21:16+02:00"
---

# CVE-2021-25374

> 8.6 HIGH

## Beschreibung

An improper authorization vulnerability in Samsung Members "samsungrewards" scheme for deeplink in versions 2.4.83.9 in Android O(8.1) and below, and 3.9.00.9 in Android P(9.0) and above allows remote attackers to access a user data related with Samsung Account.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## Referenzen

- <https://security.samsungmobile.com/>
- <https://security.samsungmobile.com/serviceWeb.smsb>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2021-25374) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
