
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability in Samsung mobile devices prior to SMR APR-2021 Release 1 allows local attackers to access IMSI values without any permission through untrusted applications due to improper storage path of IMSI values (Samsung Mobile, MITRE CVE).
The vulnerability has a CVSS v3.1 base score indicating local attack vector, low attack complexity, and low privileges required. The scope is unchanged, with low confidentiality impact and no integrity or availability impacts (NVD Report).
The primary impact of this vulnerability is unauthorized access to IMSI (International Mobile Subscriber Identity) values, which could potentially lead to privacy breaches and tracking of mobile device users (MITRE CVE).
The vulnerability can be exploited by local attackers through untrusted applications without requiring special permissions. The attack complexity is considered low, making it relatively straightforward to exploit (NVD Report).
Samsung addressed this vulnerability in the SMR APR-2021 Release 1 security update. Users should update their devices to this version or later to protect against unauthorized IMSI access (Samsung Mobile).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."