Vulnerabilities > CVE-2021-25406 - Incorrect Authorization vulnerability in Samsung Gear S

047910
CVSS 6.5 - MEDIUM
Attack vector
ADJACENT_NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
low complexity
samsung
CWE-863

Summary

Information exposure vulnerability in Gear S Plugin prior to version 2.2.05.20122441 allows unstrusted applications to access connected BT device information.

Vulnerable Configurations

Part Description Count
Application
Samsung
1

Common Weakness Enumeration (CWE)