Skip to main content

Logging of Excessive Data

CVE-2021-25420

Severity Medium
Score 5.5/10

Summary

Improper log management vulnerability in Galaxy Watch PlugIn prior to version 2.2.05.21033151 allows attacker with log permissions to leak Wi-Fi password connected to the user smartphone within log.

  • LOW
  • LOCAL
  • NONE
  • UNCHANGED
  • NONE
  • LOW
  • HIGH
  • NONE

CWE-779 - Logging of Excessive Data

The software logs too much information, making log files hard to process and possibly hindering recovery efforts or forensic analysis after an attack.

References

Advisory Timeline

  • Published