---
cve: "CVE-2025-20977"
severity: "LOW"
cvss: 3.3
epss: "0.1%"
vendor: "Samsung Mobile"
kev: false
exploited: false
published: "2025-05-07 08:24:34"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-20T20:04:58+02:00"
---

# CVE-2025-20977

> 3.3 LOW

## Beschreibung

Use of implicit intent for sensitive communication in translation in Samsung Notes prior to version 4.4.29.23 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability.

## CVSS-Vektor

```
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Erforderlich | good |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Gering | warn |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## Referenzen

- <https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=05>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2025-20977) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
