{"api_version":"1","generated_at":"2026-07-23T14:48:28+00:00","cve":"CVE-2021-25438","urls":{"html":"https://cve.report/CVE-2021-25438","api":"https://cve.report/api/cve/CVE-2021-25438.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-25438","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-25438"},"summary":{"title":"CVE-2021-25438","description":"Improper access control vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to cause local file inclusion in webview.","state":"PUBLIC","assigner":"mobile.security@samsung.com","published_at":"2021-07-08 14:15:00","updated_at":"2022-07-25 11:11:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"https://security.samsungmobile.com/serviceWeb.smsb?year=2021&month=7","name":"https://security.samsungmobile.com/serviceWeb.smsb?year=2021&month=7","refsource":"MISC","tags":[],"title":"Samsung Mobile Security","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-25438","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-25438","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"25438","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"google","cpe5":"android","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"25438","vulnerable":"-1","versionEndIncluding":"8.1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"google","cpe5":"android","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"25438","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"samsung","cpe5":"members","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"25438","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"samsung","cpe5":"members","cpe6":"3.9.10.11","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"mobile.security@samsung.com","ID":"CVE-2021-25438","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Samsung Members","version":{"version_data":[{"version_affected":"<","version_name":"-","version_value":"2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above"}]}}]},"vendor_name":"Samsung Mobile"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Improper access control vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to cause local file inclusion in webview."}]},"impact":{"cvss":{"vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-284 Improper Access Control"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://security.samsungmobile.com/serviceWeb.smsb?year=2021&month=7","name":"https://security.samsungmobile.com/serviceWeb.smsb?year=2021&month=7"}]},"source":{"discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2021-07-08 14:15:00","lastModifiedDate":"2022-07-25 11:11:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":4.6},"severity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:samsung:members:*:*:*:*:*:*:*:*","versionEndExcluding":"2.4.85.11","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:o:google:android:*:*:*:*:*:*:*:*","versionEndIncluding":"8.1","cpe_name":[]}]}],"cpe_match":[]},{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:samsung:members:3.9.10.11:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:o:google:android:*:*:*:*:*:*:*:*","versionStartIncluding":"9.0","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"25438","Ordinal":"200245","Title":"CVE-2021-25438","CVE":"CVE-2021-25438","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"25438","Ordinal":"1","NoteData":"Improper access control vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to cause local file inclusion in webview.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"25438","Ordinal":"2","NoteData":"2021-07-08","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"25438","Ordinal":"3","NoteData":"2021-07-08","Type":"Other","Title":"Modified"}]}}}