CISA KEV · catalog date Nov 8, 2022 · first observed Jul 19, 2026
Evidence dossier
CVE-2021-25369
An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.
Exploited in the wild (CISA KEV since Nov 8, 2022). NVD reports CVSS 3.1 5.5. EPSS estimates 1.1% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.
- State
- PUBLISHED
- Published
- Mar 26, 2021
- Updated
- Oct 21, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCASamsung MobileOriginal evidence ↗
Record text: An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.
Inspect raw assertion
- Field
container- Value
- An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Samsung Mobile Devices Improper Access Control Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Samsung Mobile Devices Improper Access Control Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 1.12% probability · 63.81th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.011210000000; percentile 0.638130000000
FIRST EPSS · score date Aug 27, 2026 · 63.8th percentile · first observed Aug 27, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
Outside this view’s verified evidenceReason detail begins outside this selected snapshot; the state remains source-bound.
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.
Inspect raw assertion
- Field
container- Value
- An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.
Samsung Mobile Devices Improper Access Control Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Samsung Mobile Devices Improper Access Control Vulnerability
1.12% probability · 63.81th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.011210000000; percentile 0.638130000000
Applicability
Cited product scope
Grouped from 1 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
2 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "O(8.x), P(9.0), Q(10.0)", "lessThan": "SMR Mar-2021 Release 1", "versionType": "custom"}]product-bfc06cdae9e73738e7672364f70046bdc0b0c8dcf806dda71f982d32086f0748Linked exactInspect raw assertions
cpe:2.3:o:samsung:android:10.0:smr-apr-2020-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 31
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
49da0b6e-5e55-4893-8225-299e20da2dd0
cpe:2.3:o:samsung:android:9.0:smr-feb-2021-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3b9a3b41-aac9-4e23-a265-959a9852b94c
cpe:2.3:o:samsung:android:10.0:smr-jan-2020-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 37
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
91ea248a-4d4d-4a50-ac33-7098e17b7892
cpe:2.3:o:samsung:android:9.0:smr-jan-2019-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d52a71ae-3d39-4f29-806b-603fe098510a
cpe:2.3:o:samsung:android:9.0:smr-nov-2020-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 25
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a54f7006-979f-4df5-a350-77dc3a68536e
cpe:2.3:o:samsung:android:9.0:smr-jan-2020-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
10c1df2b-8371-4259-9139-7260eacee98d
cpe:2.3:o:samsung:android:10.0:smr-nov-2020-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 44
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cb4658b8-9120-48e1-8a92-3430cbc6dc9b
cpe:2.3:o:samsung:android:9.0:smr-nov-2019-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 24
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b4561f7f-6b1f-412d-a174-5f9709acf806
cpe:2.3:o:samsung:android:9.0:smr-aug-2020-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d021b217-c481-43d1-a3e6-375e40bd4fb1
cpe:2.3:o:samsung:android:10.0:smr-jul-2020-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 39
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f3a43712-94ef-4670-a2fd-4363cbe850da
cpe:2.3:o:samsung:android:10.0:smr-dec-2019-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 33
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6a0b5d2c-7aed-4330-adad-60f78a6a08da
cpe:2.3:o:samsung:android:9.0:smr-mar-2019-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 19
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bf3fe371-e773-4af6-a8dc-0fd9ef615647
cpe:2.3:o:samsung:android:9.0:smr-feb-2020-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6ab1563d-a951-4a9c-b348-0684da242b05
cpe:2.3:o:samsung:android:10.0:smr-sep-2020-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 46
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
47335942-37fb-4a1d-837a-5d0b2883ed10
cpe:2.3:o:samsung:android:10.0:smr-mar-2020-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 41
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9fa38aa3-a747-424e-b07e-f7931fa353f0
cpe:2.3:o:samsung:android:9.0:smr-apr-2020-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
18d4924f-44ab-4e63-8040-d0b96f147bc1
cpe:2.3:o:samsung:android:10.0:smr-feb-2021-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 36
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
18c71f11-7599-4ae1-b455-c7a50d8d5f4d
cpe:2.3:o:samsung:android:9.0:smr-sep-2019-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 29
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0ec7719c-8c21-4203-9ed9-e4c048fa5cf1
cpe:2.3:o:samsung:android:10.0:smr-dec-2020-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 34
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7c7b9407-d5e0-49eb-a05d-c5e02060af36
cpe:2.3:o:samsung:android:10.0:smr-aug-2020-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 32
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ef52b720-dc8c-4ef0-b20b-7fa8b192fafb
cpe:2.3:o:samsung:android:9.0:smr-apr-2019-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
858555e6-5d30-4bbf-a5cd-fd1882209abb
cpe:2.3:o:samsung:android:9.0:smr-may-2019-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 21
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9f7d7092-5423-4cd1-819d-b784106d1342
cpe:2.3:o:samsung:android:9.0:smr-nov-2018-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 23
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5a9693c8-fe11-4e03-8d4a-0d6fe77627df
cpe:2.3:o:samsung:android:9.0:smr-mar-2020-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 20
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
45104240-9d60-47ea-8582-1f912fe7a1f2
cpe:2.3:o:samsung:android:9.0:smr-dec-2020-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6986831f-0af0-4719-ba45-4485d44d6707
cpe:2.3:o:samsung:android:9.0:smr-jun-2019-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 17
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
28950ddb-004f-4e01-9bbd-f5a320556d53
cpe:2.3:o:samsung:android:9.0:smr-oct-2019-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 27
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bb304e43-dccb-42e1-8b44-0825c9c437fb
cpe:2.3:o:samsung:android:9.0:smr-jun-2020-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 18
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
48b55cf5-cf20-48f7-a806-1234436566e1
cpe:2.3:o:samsung:android:9.0:smr-aug-2019-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8150e4fa-8f29-4974-bde8-ed192879defa
cpe:2.3:o:samsung:android:10.0:smr-oct-2020-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 45
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7685db5c-c3c2-44e2-ab00-cee65c68460b
cpe:2.3:o:samsung:android:9.0:smr-sep-2020-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 30
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2427a8f0-035e-4db5-8b91-ebd8e826f6da
cpe:2.3:o:samsung:android:8.0:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
96273bc2-d835-48c8-8eaf-0fd6eaa94f09
cpe:2.3:o:samsung:android:9.0:smr-dec-2018-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
72145ba5-c781-4e36-bb39-33dd92b2f801
cpe:2.3:o:samsung:android:10.0:smr-jun-2020-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 40
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fdcc210b-4083-494c-a233-fe2ca672004b
cpe:2.3:o:samsung:android:10.0:smr-nov-2019-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 43
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cfcffc02-efef-4a4c-a9a3-8bf355e36601
cpe:2.3:o:samsung:android:10.0:smr-may-2020-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 42
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9b48628c-6780-46b4-b717-8589658b0dce
cpe:2.3:o:samsung:android:9.0:smr-feb-2019-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
08e7c018-1293-4e29-83eb-af177ca6b179
cpe:2.3:o:samsung:android:10.0:smr-feb-2020-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 35
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f10815ef-aa9d-4899-b4ef-ed7a96e46959
cpe:2.3:o:samsung:android:9.0:smr-dec-2019-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a2e3ed73-5cf8-451f-914b-123b2312110d
cpe:2.3:o:samsung:android:9.0:smr-jan-2021-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 14
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b93a5f5f-bf53-44d3-9583-811cc284df86
cpe:2.3:o:samsung:android:9.0:smr-oct-2020-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 28
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
59bf1a24-8ac5-482f-b872-38d625fc669f
cpe:2.3:o:samsung:android:10.0:smr-jan-2021-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 38
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
878aaf2d-e54a-4145-a618-81341ed4b0c8
cpe:2.3:o:samsung:android:8.1:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3e4f5c8c-af0c-47f4-a3b0-a6d924fb72bb
cpe:2.3:o:samsung:android:9.0:smr-may-2020-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 22
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7ca7ea43-3cd8-4529-9071-3fb14ee30f45
cpe:2.3:o:samsung:android:9.0:smr-jul-2019-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 15
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
60e1950a-282d-4065-aaa5-9bbb7f8d2c5d
cpe:2.3:o:samsung:android:9.0:smr-oct-2018-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 26
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9282540e-26c5-4140-9074-480db7f5de41
cpe:2.3:o:samsung:android:9.0:smr-jul-2020-r1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 16
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4996eb5e-1fab-4799-ae46-8176d74c49d6
Affected-product evidence
Accepted scope and product mapping
0 canonical links · 0 source-reported links
Applicability remains source-scoped; safety and exposure remain unassessed.
Assessments
CVSS by origin
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NAV:L/AC:L/Au:N/C:P/I:N/A:NCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NEvidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.