CVE-2025-20895: Authentication Bypass Using an Alternate Path in Galaxy Store prior to version 4.5.87.6 allows physical attackers to install arbitrary applications...

3.2 CVSS

Description

Authentication Bypass Using an Alternate Path in Galaxy Store prior to version 4.5.87.6 allows physical attackers to install arbitrary applications to bypass restrictions of Setupwizard.

Classification

CVE ID: CVE-2025-20895

CVSS Base Severity: LOW

CVSS Base Score: 3.2

CVSS Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

Vendor: Samsung Mobile

Product: Galaxy Store

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.83% (scored less or equal to compared to others)

EPSS Date: 2025-03-05 (when was this score calculated)

References

https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=01

Timeline