Improper protection of backup path configuration in Samsung Dex prior to SMR MAY-2021 Release 1 allows local attackers to get sensitive information via changing the path.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
Link | Tags |
---|---|
https://blog.oversecured.com/Two-weeks-of-securing-Samsung-devices-Part-1/ | third party advisory exploit |
https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=5 | vendor advisory |