Improper MDM policy management vulnerability in KME module prior to KCS version 1.39 allows MDM users to bypass Knox Manage authentication.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://security.samsungmobile.com/serviceWeb.smsb?year=2021&month=7 | vendor advisory |