Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access backup data from applications. User interaction is required for triggering this vulnerability.
References
| Link | Resource |
|---|---|
| https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=10 | Vendor Advisory |
Configurations
History
28 Oct 2025, 15:41
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-312 | |
| CPE | cpe:2.3:a:samsung:smart_switch:*:*:*:*:*:*:*:* | |
| First Time |
Samsung smart Switch
Samsung |
|
| References | () https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=10 - Vendor Advisory |
10 Oct 2025, 07:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-10 07:15
Updated : 2025-10-28 15:41
NVD link : CVE-2025-21060
Mitre link : CVE-2025-21060
CVE.ORG link : CVE-2025-21060
JSON object : View
Products Affected
samsung
- smart_switch
CWE
CWE-312
Cleartext Storage of Sensitive Information
