« Volver al listado

CVE-2025-20939

Estado: AnalizadaMedia (5.4)—

Improper authorization in wireless download protocol in Galaxy Watch prior to SMR Apr-2025 Release 1 allows physical attackers to update device unique identifier of Watch devices.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-20939",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-20939",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-08T13:15:47.366365Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "mobile.security@samsung.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "PHYSICAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 4.7,
        "exploitabilityScore": 0.7
      }
    ]
  },
  "affected": [
    {
      "source": "mobile.security@samsung.com",
      "affectedData": [
        {
          "vendor": "Samsung Mobile",
          "product": "Samsung Mobile Devices",
          "versions": [
            {
              "status": "unaffected",
              "version": "SMR Apr-2025 Release in Android Watch 14"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-04-08T05:15:38.293",
  "references": [
    {
      "url": "https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=04",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "mobile.security@samsung.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper authorization in wireless download protocol in Galaxy Watch prior to SMR Apr-2025 Release 1 allows physical attackers to update device unique identifier of Watch devices."
    },
    {
      "lang": "es",
      "value": "La autorización incorrecta en el protocolo de descarga inalámbrica en Galaxy Watch anterior a la versión 1 de SMR de abril de 2025 permite que atacantes físicos actualicen el identificador único del dispositivo Watch."
    }
  ],
  "lastModified": "2026-06-17T08:42:14.470",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:samsung:wear_os:5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "60AD2A4D-9915-41E5-BC98-92B43FD013ED"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:samsung:galaxy_watch:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "978A382D-C441-4463-9B16-F6BE7E4E0527"
            },
            {
              "criteria": "cpe:2.3:h:samsung:galaxy_watch_4:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "8B7CB402-94B7-494B-B527-AF7224257D16"
            },
            {
              "criteria": "cpe:2.3:h:samsung:galaxy_watch_4_classic:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "EE4113D9-FDB3-42B3-84FB-5708E255E9A1"
            },
            {
              "criteria": "cpe:2.3:h:samsung:galaxy_watch_5:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "C0FBE6B7-1633-40ED-B6FB-6E2AFCC49FB4"
            },
            {
              "criteria": "cpe:2.3:h:samsung:galaxy_watch_5_pro:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "DF3600A1-87FC-4288-B45E-5819C42608D5"
            },
            {
              "criteria": "cpe:2.3:h:samsung:galaxy_watch_6:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "1937C6F7-8634-4825-ABFC-218DEFFFC2E7"
            },
            {
              "criteria": "cpe:2.3:h:samsung:galaxy_watch_6_classic:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "3EDAFF12-E8DD-4A30-A28C-245CE283EC80"
            },
            {
              "criteria": "cpe:2.3:h:samsung:galaxy_watch_7:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "5B2F17A5-E4EA-4A6B-BE76-575C82E4308D"
            },
            {
              "criteria": "cpe:2.3:h:samsung:galaxy_watch_fe:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "1C5FAF84-EF64-4E15-A211-72274A1EABA5"
            },
            {
              "criteria": "cpe:2.3:h:samsung:galaxy_watch_ultra:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "AC6A3702-DCD4-4C97-9F07-D35959A29EE1"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "mobile.security@samsung.com"
}