« Back to list

CVE-2025-53079

Status: AnalyzedMedium (4.9)—

Absolute Path Traversal in Samsung DMS(Data Management Server) allows authenticated attacker (Administrator) to read sensitive files

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2025-53079",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-53079",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-07-29T14:49:55.925035Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "PSIRT@samsung.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "PSIRT@samsung.com",
      "affectedData": [
        {
          "vendor": "Samsung Electronics",
          "product": "Data Management Server",
          "versions": [
            {
              "status": "affected",
              "version": "2.0.0",
              "lessThan": "2.3.13.1",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "2.5.0.17",
              "lessThan": "2.6.14.1",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "2.7.0.15",
              "lessThan": "2.9.3.6",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-07-29T05:15:31.980",
  "references": [
    {
      "url": "https://security.samsungda.com/securityUpdates.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "PSIRT@samsung.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "PSIRT@samsung.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-36"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Absolute Path Traversal in Samsung DMS(Data Management Server) allows authenticated attacker (Administrator) to read sensitive files"
    },
    {
      "lang": "es",
      "value": "Path Traversal absoluto en Samsung DMS(Data Management Server) permite que un atacante autenticado (administrador) lea archivos confidenciales"
    }
  ],
  "lastModified": "2026-06-17T09:37:35.773",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:samsung:data_management_server_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "620C0889-6BB6-477F-BBB3-F23A81F81254",
              "versionEndExcluding": "2.3.13.1",
              "versionStartIncluding": "2.0.0"
            },
            {
              "criteria": "cpe:2.3:o:samsung:data_management_server_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E2362518-8040-4FFD-9567-DC22015DD7EB",
              "versionEndExcluding": "2.6.14.1",
              "versionStartIncluding": "2.5.0.17"
            },
            {
              "criteria": "cpe:2.3:o:samsung:data_management_server_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "51C84E33-C218-4A9A-B0F0-3B4DA1E90AA5",
              "versionEndExcluding": "2.9.3.6",
              "versionStartIncluding": "2.7.0.15"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:samsung:data_management_server:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "BFF4DB9B-396F-428D-BCDD-F2DE7AF45884"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "PSIRT@samsung.com"
}