CVE Vulnerabilities

CVE-2025-20912

Insecure Storage of Sensitive Information

Published: Mar 06, 2025 | Modified: Feb 02, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Incorrect default permission in DiagMonAgent prior to SMR Mar-2025 Release 1 allows local attackers to access data within Galaxy Watch.

Weakness

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

Affected Software

NameVendorStart VersionEnd Version
Wear_osSamsung5.0 (including)5.0 (including)

References