CVE Vulnerabilities

CVE-2025-58107

Cleartext Transmission of Sensitive Information

Published: Mar 02, 2026 | Modified: Mar 02, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In Microsoft Exchange through 2019, Exchange ActiveSync (EAS) configurations on on-premises servers may transmit sensitive data from Samsung mobile devices in cleartext, including the users name, e-mail address, device ID, bearer token, and base64-encoded password.

Weakness

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Potential Mitigations

References