2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2021-25424" ,
"sourceIdentifier" : "mobile.security@samsung.com" ,
"published" : "2021-06-11T15:15:10.963" ,
"lastModified" : "2021-06-17T14:40:45.187" ,
"vulnStatus" : "Analyzed" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Improper authentication vulnerability in Tizen bluetooth-frwk prior to Firmware update JUN-2021 Release allows bluetooth attacker to take over the user's bluetooth device without user awareness."
} ,
{
"lang" : "es" ,
"value" : "Una vulnerabilidad de autenticaci\u00f3n inapropiada en Tizen bluetooth-frwk anterior a la Actualizaci\u00f3n de Firmware JUN-2021, permite a un atacante tomar el control del dispositivo bluetooth del usuario sin que \u00e9ste lo sepa"
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" ,
"attackVector" : "ADJACENT_NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 8.8 ,
"baseSeverity" : "HIGH"
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 5.9
}
] ,
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:A/AC:L/Au:N/C:P/I:P/A:P" ,
"accessVector" : "ADJACENT_NETWORK" ,
"accessComplexity" : "LOW" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "PARTIAL" ,
"integrityImpact" : "PARTIAL" ,
"availabilityImpact" : "PARTIAL" ,
"baseScore" : 5.8
} ,
"baseSeverity" : "MEDIUM" ,
"exploitabilityScore" : 6.5 ,
"impactScore" : 6.4 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : false
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-287"
}
]
} ,
{
"source" : "mobile.security@samsung.com" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-287"
}
]
}
] ,
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:samsung:galaxy_watch_active_2_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "5.5" ,
"matchCriteriaId" : "63010A7C-58DC-468C-BA3C-F55098E8DEFB"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:samsung:galaxy_watch_active_2:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "008A8838-4273-49EA-8ABE-590BE4765EE0"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:samsung:galaxy_watch_active_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "5.5" ,
"matchCriteriaId" : "968977C3-E441-4758-9FD7-E10CA68F095C"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:samsung:galaxy_watch_active:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "43AC7998-096D-4F7C-90BF-F024DEA68569"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:samsung:galaxy_watch_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "5.5" ,
"matchCriteriaId" : "57C16DE2-8E1D-4F05-BBA2-931A102AA947"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:samsung:galaxy_watch:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "978A382D-C441-4463-9B16-F6BE7E4E0527"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:samsung:galaxy_watch_3_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "5.5" ,
"matchCriteriaId" : "1F5CDA8B-A7C2-40B7-85AC-EDD147002D11"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:samsung:galaxy_watch_3:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E06E024E-72D6-41A0-A780-408C12008CFC"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:samsung:gear_s3_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "5.5" ,
"matchCriteriaId" : "1470254A-C484-4039-A69B-FA2D918764DB"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:samsung:gear_s3:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "EB6F5890-C7A5-45B2-BADE-118B53BE2667"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:samsung:gear_s2_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "5.5" ,
"matchCriteriaId" : "97204E57-9899-4CEB-9E6F-9479A2CB831C"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:samsung:gear_s2:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "80E04318-D715-4263-A869-C9203EB7CE75"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:samsung:gear_s_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "5.5" ,
"matchCriteriaId" : "AAA73BF3-0560-447C-95CC-D04718BEE158"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:samsung:gear_s:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "15C8050C-4FFB-4CE9-AC2E-927C43D0A5ED"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:samsung:gear_2_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "5.5" ,
"matchCriteriaId" : "7413DA6A-0A6F-4BDE-80A3-EBD4B9B2FBE3"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:samsung:gear_2:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A58D5FF1-9573-4059-9C38-4C6B45812896"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:samsung:gear_2_neo_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "5.5" ,
"matchCriteriaId" : "385D6A09-9D98-4A97-AAAC-FB599B18B1CE"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:samsung:gear_2_neo:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "18433CF4-99AC-4925-8E96-20AF0910507F"
}
]
}
]
}
] ,
"references" : [
{
"url" : "https://security.samsungmobile.com/serviceWeb.smsb?year=2021&month=6" ,
"source" : "mobile.security@samsung.com" ,
"tags" : [
"Vendor Advisory"
]
}
]
}