{"containers":{"cna":{"affected":[{"product":"Samsung Account","vendor":"Samsung Mobile","versions":[{"lessThan":"10.8.0.4","status":"affected","version":"Android P(9.0) and below","versionType":"custom"},{"lessThan":"12.1.1.3","status":"affected","version":"Android Q(10.0) and above","versionType":"custom"}]}],"descriptions":[{"lang":"en","value":"Using unsafe PendingIntent in Samsung Account in versions 10.8.0.4 in Android P(9.0) and below, and 12.1.1.3 in Android Q(10.0) and above allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-285","description":"CWE-285 Improper Authorization","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2021-04-09T17:40:41.000Z","orgId":"3af57064-a867-422c-b2ad-40307b65c458","shortName":"Samsung Mobile"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://security.samsungmobile.com/"},{"tags":["x_refsource_CONFIRM"],"url":"https://security.samsungmobile.com/serviceWeb.smsb"}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 0.0.9"},"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"mobile.security@samsung.com","ID":"CVE-2021-25381","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Samsung Account","version":{"version_data":[{"version_affected":"<","version_name":"Android P(9.0) and below","version_value":"10.8.0.4"},{"version_affected":"<","version_name":"Android Q(10.0) and above","version_value":"12.1.1.3"}]}}]},"vendor_name":"Samsung Mobile"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Using unsafe PendingIntent in Samsung Account in versions 10.8.0.4 in Android P(9.0) and below, and 12.1.1.3 in Android Q(10.0) and above allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-285 Improper Authorization"}]}]},"references":{"reference_data":[{"name":"https://security.samsungmobile.com/","refsource":"CONFIRM","url":"https://security.samsungmobile.com/"},{"name":"https://security.samsungmobile.com/serviceWeb.smsb","refsource":"CONFIRM","url":"https://security.samsungmobile.com/serviceWeb.smsb"}]},"source":{"discovery":"UNKNOWN"}}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-03T20:03:05.642Z"},"title":"CVE Program Container","references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://security.samsungmobile.com/"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://security.samsungmobile.com/serviceWeb.smsb"}]}]},"cveMetadata":{"assignerOrgId":"3af57064-a867-422c-b2ad-40307b65c458","assignerShortName":"Samsung Mobile","cveId":"CVE-2021-25381","datePublished":"2021-04-09T17:40:41.000Z","dateReserved":"2021-01-19T00:00:00.000Z","dateUpdated":"2024-08-03T20:03:05.642Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"}