- Description
- Improper access control in Mdecservice prior to SMR Apr-2025 Release 1 allows local attackers to access arbitrary files with system privilege.
- Source
- mobile.security@samsung.com
- NVD status
- Analyzed
- Products
- android
CVSS 3.1
- Type
- Secondary
- Base score
- 5.5
- Impact score
- 3.6
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity
- MEDIUM
- Hype score
- Not currently trending
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:samsung:android:15.0:smr-feb-2025-r1:*:*:*:*:*:*",
"matchCriteriaId": "7A5F4E59-BD59-41C8-82B2-A3C52E7125AA",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:samsung:android:15.0:smr-jan-2025-r1:*:*:*:*:*:*",
"matchCriteriaId": "F878069B-37C9-4636-8C31-526B610A0AFA",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:samsung:android:15.0:smr-mar-2025-r1:*:*:*:*:*:*",
"matchCriteriaId": "FC6E2318-BD4E-4540-82C3-0D461C691119",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]