CVE-2025-58107

In Microsoft Exchange through 2019, Exchange ActiveSync (EAS) configurations on on-premises servers may transmit sensitive data from Samsung mobile devices in cleartext, including the user's name, e-mail address, device ID, bearer token, and base64-encoded password.
Configurations

No configuration.

History

17 Jun 2026, 09:43

Type Values Removed Values Added
Summary
  • (es) En Microsoft Exchange hasta 2019, las configuraciones de Exchange ActiveSync (EAS) en servidores locales pueden transmitir datos sensibles de dispositivos móviles Samsung en texto claro, incluyendo el nombre de usuario, la dirección de correo electrónico, el ID del dispositivo, el token de portador y la contraseña codificada en base64.

02 Mar 2026, 19:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-319

02 Mar 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-02 15:16

Updated : 2026-06-17 09:43


NVD link : CVE-2025-58107

Mitre link : CVE-2025-58107

CVE.ORG link : CVE-2025-58107


JSON object : View

Products Affected

No product.

CWE
CWE-319

Cleartext Transmission of Sensitive Information