CVE-2025-58107

In Microsoft Exchange through 2019, Exchange ActiveSync (EAS) configurations on on-premises servers may transmit sensitive data from Samsung mobile devices in cleartext, including the user's name, e-mail address, device ID, bearer token, and base64-encoded password.
Configurations

No configuration.

History

02 Mar 2026, 19:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-319

02 Mar 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-02 15:16

Updated : 2026-03-02 20:29


NVD link : CVE-2025-58107

Mitre link : CVE-2025-58107

CVE.ORG link : CVE-2025-58107


JSON object : View

Products Affected

No product.

CWE
CWE-319

Cleartext Transmission of Sensitive Information