CVE Vulnerabilities

CVE-2025-20945

Insecure Storage of Sensitive Information

Published: Apr 08, 2025 | Modified: Jan 27, 2026
CVSS 3.x
6.2
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Improper access control in Galaxy Watch prior to SMR Apr-2025 Release 1 allows local attackers to access sensitive information of Galaxy watch.

Weakness

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

Affected Software

NameVendorStart VersionEnd Version
Wear_osSamsung5.0 (including)5.0 (including)

References