CVE-2025-53077 (GCVE-0-2025-53077)
Vulnerability from cvelistv5
Published
2025-07-29 05:03
Modified
2025-07-29 15:06
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-698 - Execution After Redirect (EAR)
Summary
An execution after redirect in Samsung DMS(Data Management Server) allows attackers to execute limited functions without permissions. An attacker could compromise the integrity of the platform by executing this vulnerability.
References
► | URL | Tags | |||||
---|---|---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
Samsung Electronics | DMS(Data Management Server) |
Version: 2.0.0 < 2.3.13.1 Version: 2.5.0.17 < 2.6.14.1 Version: 2.7.0.15 < 2.9.3.6 |
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-53077", "options": [ { "Exploitation": "none" }, { "Automatable": "yes" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "timestamp": "2025-07-29T15:06:15.557705Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-07-29T15:06:50.737Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "defaultStatus": "unaffected", "product": "DMS(Data Management Server)", "vendor": "Samsung Electronics", "versions": [ { "lessThan": "2.3.13.1", "status": "affected", "version": "2.0.0", "versionType": "custom" }, { "lessThan": "2.6.14.1", "status": "affected", "version": "2.5.0.17", "versionType": "custom" }, { "lessThan": "2.9.3.6", "status": "affected", "version": "2.7.0.15", "versionType": "custom" } ] } ], "credits": [ { "lang": "en", "type": "finder", "value": "Noam Moshe of Claroty Team82" } ], "datePublic": "2025-07-29T05:00:00.000Z", "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "An execution after redirect in Samsung DMS(Data Management Server) allows attackers to execute limited functions without permissions. An attacker could compromise the integrity of the platform by executing this vulnerability." } ], "value": "An execution after redirect in Samsung DMS(Data Management Server) allows attackers to execute limited functions without permissions. An attacker could compromise the integrity of the platform by executing this vulnerability." } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "LOW", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-698", "description": "CWE-698 Execution After Redirect (EAR)", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-07-29T05:03:41.034Z", "orgId": "ca193ba2-0cff-4e34-b04e-1ea07103c6fe", "shortName": "samsung.tv_appliance" }, "references": [ { "url": "https://security.samsungda.com/securityUpdates.html" } ], "source": { "discovery": "UNKNOWN" }, "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "ca193ba2-0cff-4e34-b04e-1ea07103c6fe", "assignerShortName": "samsung.tv_appliance", "cveId": "CVE-2025-53077", "datePublished": "2025-07-29T05:03:41.034Z", "dateReserved": "2025-06-24T23:17:22.556Z", "dateUpdated": "2025-07-29T15:06:50.737Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1", "vulnerability-lookup:meta": { "nvd": "{\"cve\":{\"id\":\"CVE-2025-53077\",\"sourceIdentifier\":\"PSIRT@samsung.com\",\"published\":\"2025-07-29T05:15:31.640\",\"lastModified\":\"2025-08-11T19:05:41.957\",\"vulnStatus\":\"Analyzed\",\"cveTags\":[],\"descriptions\":[{\"lang\":\"en\",\"value\":\"An execution after redirect in Samsung DMS(Data Management Server) allows attackers to execute limited functions without permissions. An attacker could compromise the integrity of the platform by executing this vulnerability.\"},{\"lang\":\"es\",\"value\":\"Una ejecuci\u00f3n posterior a una redirecci\u00f3n en Samsung DMS(Data Management Server) permite a los atacantes ejecutar funciones limitadas sin permisos. Un atacante podr\u00eda comprometer la integridad de la plataforma al ejecutar esta vulnerabilidad.\"}],\"metrics\":{\"cvssMetricV31\":[{\"source\":\"PSIRT@samsung.com\",\"type\":\"Secondary\",\"cvssData\":{\"version\":\"3.1\",\"vectorString\":\"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L\",\"baseScore\":6.5,\"baseSeverity\":\"MEDIUM\",\"attackVector\":\"NETWORK\",\"attackComplexity\":\"LOW\",\"privilegesRequired\":\"NONE\",\"userInteraction\":\"NONE\",\"scope\":\"UNCHANGED\",\"confidentialityImpact\":\"NONE\",\"integrityImpact\":\"LOW\",\"availabilityImpact\":\"LOW\"},\"exploitabilityScore\":3.9,\"impactScore\":2.5}]},\"weaknesses\":[{\"source\":\"PSIRT@samsung.com\",\"type\":\"Secondary\",\"description\":[{\"lang\":\"en\",\"value\":\"CWE-698\"}]}],\"configurations\":[{\"operator\":\"AND\",\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:samsung:data_management_server_firmware:*:*:*:*:*:*:*:*\",\"versionStartIncluding\":\"2.0.0\",\"versionEndExcluding\":\"2.3.13.1\",\"matchCriteriaId\":\"620C0889-6BB6-477F-BBB3-F23A81F81254\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:samsung:data_management_server_firmware:*:*:*:*:*:*:*:*\",\"versionStartIncluding\":\"2.5.0.17\",\"versionEndExcluding\":\"2.6.14.1\",\"matchCriteriaId\":\"E2362518-8040-4FFD-9567-DC22015DD7EB\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:samsung:data_management_server_firmware:*:*:*:*:*:*:*:*\",\"versionStartIncluding\":\"2.7.0.15\",\"versionEndExcluding\":\"2.9.3.6\",\"matchCriteriaId\":\"51C84E33-C218-4A9A-B0F0-3B4DA1E90AA5\"}]},{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":false,\"criteria\":\"cpe:2.3:h:samsung:data_management_server:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"BFF4DB9B-396F-428D-BCDD-F2DE7AF45884\"}]}]}],\"references\":[{\"url\":\"https://security.samsungda.com/securityUpdates.html\",\"source\":\"PSIRT@samsung.com\",\"tags\":[\"Vendor Advisory\"]}]}}", "vulnrichment": { "containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2025-53077\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"yes\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2025-07-29T15:06:15.557705Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2025-07-29T15:06:35.265Z\"}}], \"cna\": {\"source\": {\"discovery\": \"UNKNOWN\"}, \"credits\": [{\"lang\": \"en\", \"type\": \"finder\", \"value\": \"Noam Moshe of Claroty Team82\"}], \"metrics\": [{\"format\": \"CVSS\", \"cvssV3_1\": {\"scope\": \"UNCHANGED\", \"version\": \"3.1\", \"baseScore\": 6.5, \"attackVector\": \"NETWORK\", \"baseSeverity\": \"MEDIUM\", \"vectorString\": \"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L\", \"integrityImpact\": \"LOW\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"LOW\", \"availabilityImpact\": \"LOW\", \"privilegesRequired\": \"NONE\", \"confidentialityImpact\": \"NONE\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"GENERAL\"}]}], \"affected\": [{\"vendor\": \"Samsung Electronics\", \"product\": \"DMS(Data Management Server)\", \"versions\": [{\"status\": \"affected\", \"version\": \"2.0.0\", \"lessThan\": \"2.3.13.1\", \"versionType\": \"custom\"}, {\"status\": \"affected\", \"version\": \"2.5.0.17\", \"lessThan\": \"2.6.14.1\", \"versionType\": \"custom\"}, {\"status\": \"affected\", \"version\": \"2.7.0.15\", \"lessThan\": \"2.9.3.6\", \"versionType\": \"custom\"}], \"defaultStatus\": \"unaffected\"}], \"datePublic\": \"2025-07-29T05:00:00.000Z\", \"references\": [{\"url\": \"https://security.samsungda.com/securityUpdates.html\"}], \"x_generator\": {\"engine\": \"Vulnogram 0.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"An execution after redirect in Samsung DMS(Data Management Server) allows attackers to execute limited functions without permissions. An attacker could compromise the integrity of the platform by executing this vulnerability.\", \"supportingMedia\": [{\"type\": \"text/html\", \"value\": \"An execution after redirect in Samsung DMS(Data Management Server) allows attackers to execute limited functions without permissions. An attacker could compromise the integrity of the platform by executing this vulnerability.\", \"base64\": false}]}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-698\", \"description\": \"CWE-698 Execution After Redirect (EAR)\"}]}], \"providerMetadata\": {\"orgId\": \"ca193ba2-0cff-4e34-b04e-1ea07103c6fe\", \"shortName\": \"samsung.tv_appliance\", \"dateUpdated\": \"2025-07-29T05:03:41.034Z\"}}}", "cveMetadata": "{\"cveId\": \"CVE-2025-53077\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2025-07-29T15:06:50.737Z\", \"dateReserved\": \"2025-06-24T23:17:22.556Z\", \"assignerOrgId\": \"ca193ba2-0cff-4e34-b04e-1ea07103c6fe\", \"datePublished\": \"2025-07-29T05:03:41.034Z\", \"assignerShortName\": \"samsung.tv_appliance\"}", "dataType": "CVE_RECORD", "dataVersion": "5.1" } } }
Loading…
Loading…
Sightings
Author | Source | Type | Date |
---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…