CVE-2021-25369

MEDIUM(6.2)KEV

Samsung Mobile Devices Improper Access Control Vulnerability

Description

CVE-2021-25369 is an improper access control vulnerability affecting Samsung Mobile Devices, specifically in the sec_log file handler prior to the SMR MAR-2021 Release 1 security update. This information disclosure weakness allows a local attacker — without any special privileges — to read sensitive kernel information from userspace, bypassing the isolation that should exist between kernel and user-level processes. While the vulnerability does not allow data modification or system disruption, the exposure of kernel internals could be leveraged to facilitate further attacks against Samsung Android devices. CISA has added CVE-2021-25369 to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild.

KEV Information

Vendor
Samsung
Product
Mobile Devices
Date Added
November 8, 2022
Due Date
November 29, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NOpen in Calculator
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.5
Impact Score
3.6

CWEs

Affected Products

VendorProductVersion
samsungandroid8.0; 8.1; 9.0; 10.0

Multiple CVSS Assessments

Source: [email protected](Secondary)
6.2
MEDIUM

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Source: [email protected](Primary)
5.5
MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

References

Weakness Type

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

CWE-200 describes a weakness where software exposes sensitive information to actors who are not authorized to access it. In CVE-2021-25369, the sec_log file on Samsung Android devices lacks proper access controls, allowing unprivileged userspace processes to read kernel-level log data that should be restricted.

Learn more: CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor

Impact Analysis

CVE-2021-25369 carries a CVSS 3.1 score of 6.2 (Medium), but its real-world significance is amplified by its KEV status. Attack Vector (Local): exploitation requires local access to the Samsung Android device, meaning an attacker must either have physical access or already have code execution on the device. Attack Complexity (Low): no special conditions or race conditions are needed to exploit this vulnerability. Privileges Required (None): any unprivileged application or user on the device can trigger the information disclosure. Confidentiality Impact (High): sensitive kernel information — which could include memory addresses, kernel configuration data, or internal state — is exposed to userspace, which could help an attacker bypass kernel security mitigations such as ASLR. Integrity and Availability: there is no direct impact on data integrity or system availability, making this a pure information disclosure issue; however, leaked kernel data can be a critical enabler for chaining additional exploits.

Exploit Maturity

CISA has confirmed active exploitation of CVE-2021-25369 against Samsung Mobile Devices, as evidenced by its inclusion in the Known Exploited Vulnerabilities catalog with a remediation deadline of November 29, 2022. No explicit exploit-tagged references appear in the available references, but active exploitation is confirmed. The EPSS score of 0.156% (36th percentile) suggests that while automated exploit scanning is not widespread, the KEV designation confirms targeted exploitation has occurred. This vulnerability is most likely exploited as part of a multi-stage attack chain where the kernel information disclosure enables subsequent privilege escalation or sandbox escape attempts.

Remediation

  1. Apply the Samsung SMR MAR-2021 Release 1 update — Samsung's March 2021 Security Maintenance Release addresses CVE-2021-25369 by correcting the access controls on the sec_log file. Install this update immediately on all affected Samsung Android devices.
  2. If the update cannot be applied, discontinue use — Per CISA's KEV required action: "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable."
  3. Restrict sideloading and untrusted applications — Since exploitation requires local code execution, restrict installation of applications from untrusted sources (disable "Install unknown apps" on affected devices).
  4. Enable mobile device management (MDM) controls — Use MDM policies to enforce security update compliance and detect devices that have not applied the March 2021 SMR.
  5. Monitor for anomalous kernel log access — Review Android security event logs for unusual access patterns to system log files from unprivileged applications, which could indicate exploitation attempts.

Technical Details

CVE-2021-25369 stems from an improper access control (CWE-200) implementation in the Samsung Android kernel's sec_log file, which is a debug logging interface. The vulnerability occurs because the file's permissions or access control checks are insufficiently restrictive, allowing userspace processes — which should be isolated from kernel internals — to read the file's contents directly. The CVSS vector string CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N reflects that exploitation is local (physical or existing code execution required), trivially easy (no complexity or privilege needed), and results in full confidentiality compromise of the kernel information contained in the log. Kernel log data can include memory layout hints such as kernel symbol addresses or KASLR offsets, which are valuable for defeating kernel exploit mitigations. The scope remains unchanged (S:U), meaning the vulnerability does not inherently allow escaping the device's security boundary on its own.

Frequently Asked Questions

Is CVE-2021-25369 being actively exploited?

Yes. CISA has added CVE-2021-25369 to its Known Exploited Vulnerabilities (KEV) catalog, confirming that this vulnerability has been actively exploited in the wild. The KEV remediation deadline was November 29, 2022, indicating urgency for federal agencies and strongly suggesting real-world exploitation.

What products are affected by CVE-2021-25369?

CVE-2021-25369 affects Samsung Android Mobile Devices running software versions prior to the SMR MAR-2021 Release 1 (Samsung's March 2021 Security Maintenance Release). The vulnerability is in the sec_log file handler within Samsung's Android kernel customization.

How do I fix CVE-2021-25369?

Apply Samsung's SMR MAR-2021 Release 1 security update, which corrects the improper access controls on the sec_log file. If the update cannot be applied, CISA recommends discontinuing use of the affected device. Refer to Samsung's security advisory at security.samsungmobile.com for detailed guidance.

How severe is CVE-2021-25369?

CVE-2021-25369 has a CVSS 3.1 score of 6.2 (Medium severity). The EPSS score of 0.156% places it at the 36th percentile for exploitation probability. Despite the moderate CVSS rating, the KEV status elevates its practical risk significantly, as active exploitation has been confirmed by CISA.

CVSS Score

6.2
MEDIUM(6.2)

EPSS Score

EPSS Score1.12%
EPSS Percentile63.6%

Dates

PublishedMarch 26, 2021
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.