« Volver al listado

CVE-2025-20911

Estado: AnalizadaMedia (4.4)—

Improper access control in sem_wifi service prior to SMR Mar-2025 Release 1 allows privileged local attackers to update MAC address of Galaxy Watch.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-20911",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-20911",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-03-06T15:02:21.259229Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "mobile.security@samsung.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.4,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 0.8
      }
    ]
  },
  "affected": [
    {
      "source": "mobile.security@samsung.com",
      "affectedData": [
        {
          "vendor": "Samsung Mobile",
          "product": "Samsung Mobile Devices",
          "versions": [
            {
              "status": "unaffected",
              "version": "SMR Mar-2025 Release in Android Watch 14"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-03-06T05:15:17.653",
  "references": [
    {
      "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=03",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "mobile.security@samsung.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper access control in sem_wifi service prior to SMR Mar-2025 Release 1 allows privileged local attackers to update MAC address of Galaxy Watch."
    },
    {
      "lang": "es",
      "value": "El control de acceso inadecuado en el servicio sem_wifi anterior a SMR Mar-2025 Release 1 permite que atacantes locales privilegiados actualicen la dirección MAC de Galaxy Watch."
    }
  ],
  "lastModified": "2026-06-17T08:42:11.473",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:samsung:wear_os:5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "60AD2A4D-9915-41E5-BC98-92B43FD013ED"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:samsung:galaxy_watch:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "978A382D-C441-4463-9B16-F6BE7E4E0527"
            },
            {
              "criteria": "cpe:2.3:h:samsung:galaxy_watch_4:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "8B7CB402-94B7-494B-B527-AF7224257D16"
            },
            {
              "criteria": "cpe:2.3:h:samsung:galaxy_watch_4_classic:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "EE4113D9-FDB3-42B3-84FB-5708E255E9A1"
            },
            {
              "criteria": "cpe:2.3:h:samsung:galaxy_watch_5:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "C0FBE6B7-1633-40ED-B6FB-6E2AFCC49FB4"
            },
            {
              "criteria": "cpe:2.3:h:samsung:galaxy_watch_5_pro:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "DF3600A1-87FC-4288-B45E-5819C42608D5"
            },
            {
              "criteria": "cpe:2.3:h:samsung:galaxy_watch_6:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "1937C6F7-8634-4825-ABFC-218DEFFFC2E7"
            },
            {
              "criteria": "cpe:2.3:h:samsung:galaxy_watch_6_classic:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "3EDAFF12-E8DD-4A30-A28C-245CE283EC80"
            },
            {
              "criteria": "cpe:2.3:h:samsung:galaxy_watch_7:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "5B2F17A5-E4EA-4A6B-BE76-575C82E4308D"
            },
            {
              "criteria": "cpe:2.3:h:samsung:galaxy_watch_fe:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "1C5FAF84-EF64-4E15-A211-72274A1EABA5"
            },
            {
              "criteria": "cpe:2.3:h:samsung:galaxy_watch_ultra:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "AC6A3702-DCD4-4C97-9F07-D35959A29EE1"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "mobile.security@samsung.com"
}