CVE Vulnerabilities

CVE-2021-25337

Improper Privilege Management

Published: Mar 04, 2021 | Modified: Feb 14, 2025
CVSS 3.x
7.1
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Android Samsung 9.0-smr-apr-2019-r1 (including) 9.0-smr-apr-2019-r1 (including)
Android Samsung 9.0-smr-apr-2020-r1 (including) 9.0-smr-apr-2020-r1 (including)
Android Samsung 9.0-smr-aug-2019-r1 (including) 9.0-smr-aug-2019-r1 (including)
Android Samsung 9.0-smr-aug-2020-r1 (including) 9.0-smr-aug-2020-r1 (including)
Android Samsung 9.0-smr-dec-2018-r1 (including) 9.0-smr-dec-2018-r1 (including)
Android Samsung 9.0-smr-dec-2019-r1 (including) 9.0-smr-dec-2019-r1 (including)
Android Samsung 9.0-smr-dec-2020-r1 (including) 9.0-smr-dec-2020-r1 (including)
Android Samsung 9.0-smr-feb-2019-r1 (including) 9.0-smr-feb-2019-r1 (including)
Android Samsung 9.0-smr-feb-2020-r1 (including) 9.0-smr-feb-2020-r1 (including)
Android Samsung 9.0-smr-feb-2021-r1 (including) 9.0-smr-feb-2021-r1 (including)
Android Samsung 9.0-smr-jan-2019-r1 (including) 9.0-smr-jan-2019-r1 (including)
Android Samsung 9.0-smr-jan-2020-r1 (including) 9.0-smr-jan-2020-r1 (including)
Android Samsung 9.0-smr-jan-2021-r1 (including) 9.0-smr-jan-2021-r1 (including)
Android Samsung 9.0-smr-jul-2019-r1 (including) 9.0-smr-jul-2019-r1 (including)
Android Samsung 9.0-smr-jul-2020-r1 (including) 9.0-smr-jul-2020-r1 (including)
Android Samsung 9.0-smr-jun-2019-r1 (including) 9.0-smr-jun-2019-r1 (including)
Android Samsung 9.0-smr-jun-2020-r1 (including) 9.0-smr-jun-2020-r1 (including)
Android Samsung 9.0-smr-mar-2019-r1 (including) 9.0-smr-mar-2019-r1 (including)
Android Samsung 9.0-smr-mar-2020-r1 (including) 9.0-smr-mar-2020-r1 (including)
Android Samsung 9.0-smr-may-2019-r1 (including) 9.0-smr-may-2019-r1 (including)
Android Samsung 9.0-smr-may-2020-r1 (including) 9.0-smr-may-2020-r1 (including)
Android Samsung 9.0-smr-nov-2018-r1 (including) 9.0-smr-nov-2018-r1 (including)
Android Samsung 9.0-smr-nov-2019-r1 (including) 9.0-smr-nov-2019-r1 (including)
Android Samsung 9.0-smr-nov-2020-r1 (including) 9.0-smr-nov-2020-r1 (including)
Android Samsung 9.0-smr-oct-2018-r1 (including) 9.0-smr-oct-2018-r1 (including)
Android Samsung 9.0-smr-oct-2019-r1 (including) 9.0-smr-oct-2019-r1 (including)
Android Samsung 9.0-smr-oct-2020-r1 (including) 9.0-smr-oct-2020-r1 (including)
Android Samsung 9.0-smr-sep-2019-r1 (including) 9.0-smr-sep-2019-r1 (including)
Android Samsung 9.0-smr-sep-2020-r1 (including) 9.0-smr-sep-2020-r1 (including)
Android Samsung 10.0-smr-apr-2020-r1 (including) 10.0-smr-apr-2020-r1 (including)
Android Samsung 10.0-smr-aug-2020-r1 (including) 10.0-smr-aug-2020-r1 (including)
Android Samsung 10.0-smr-dec-2019-r1 (including) 10.0-smr-dec-2019-r1 (including)
Android Samsung 10.0-smr-dec-2020-r1 (including) 10.0-smr-dec-2020-r1 (including)
Android Samsung 10.0-smr-feb-2020-r1 (including) 10.0-smr-feb-2020-r1 (including)
Android Samsung 10.0-smr-feb-2021-r1 (including) 10.0-smr-feb-2021-r1 (including)
Android Samsung 10.0-smr-jan-2020-r1 (including) 10.0-smr-jan-2020-r1 (including)
Android Samsung 10.0-smr-jan-2021-r1 (including) 10.0-smr-jan-2021-r1 (including)
Android Samsung 10.0-smr-jul-2020-r1 (including) 10.0-smr-jul-2020-r1 (including)
Android Samsung 10.0-smr-jun-2020-r1 (including) 10.0-smr-jun-2020-r1 (including)
Android Samsung 10.0-smr-mar-2020-r1 (including) 10.0-smr-mar-2020-r1 (including)
Android Samsung 10.0-smr-may-2020-r1 (including) 10.0-smr-may-2020-r1 (including)
Android Samsung 10.0-smr-nov-2019-r1 (including) 10.0-smr-nov-2019-r1 (including)
Android Samsung 10.0-smr-nov-2020-r1 (including) 10.0-smr-nov-2020-r1 (including)
Android Samsung 10.0-smr-oct-2020-r1 (including) 10.0-smr-oct-2020-r1 (including)
Android Samsung 10.0-smr-sep-2020-r1 (including) 10.0-smr-sep-2020-r1 (including)
Android Samsung 11.0-smr-dec-2020-r1 (including) 11.0-smr-dec-2020-r1 (including)
Android Samsung 11.0-smr-feb-2021-r1 (including) 11.0-smr-feb-2021-r1 (including)
Android Samsung 11.0-smr-jan-2021-r1 (including) 11.0-smr-jan-2021-r1 (including)

Potential Mitigations

References