ID

VAR-202112-0548


CVE

CVE-2021-25516


TITLE

Android  Vulnerability in handling exceptional conditions in

Trust: 0.8

sources: JVNDB: JVNDB-2021-016953

DESCRIPTION

An improper check or handling of exceptional conditions in Exynos baseband prior to SMR Dec-2021 Release 1 allows attackers to track locations. Android Exists in a vulnerability in handling exceptional conditions.Information may be obtained. Samsung RRC MeasurementReport is a radio resource control protocol measurement report for Samsung mobile devices. The vulnerability is caused by the lack of correct RRC security variable checks in the Exynos baseband. Attackers can use this vulnerability to track location

Trust: 2.16

sources: NVD: CVE-2021-25516 // JVNDB: JVNDB-2021-016953 // CNVD: CNVD-2025-02725

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-02725

AFFECTED PRODUCTS

vendor:googlemodel:androidscope:eqversion:10.0

Trust: 1.0

vendor:googlemodel:androidscope:eqversion:9.0

Trust: 1.0

vendor:googlemodel:androidscope:eqversion:11.0

Trust: 1.0

vendor:googlemodel:androidscope:eqversion: -

Trust: 0.8

vendor:googlemodel:androidscope: - version: -

Trust: 0.8

vendor:samsungmodel:mobile devices rscope: - version: -

Trust: 0.6

vendor:samsungmodel:mobile devices qscope: - version: -

Trust: 0.6

vendor:samsungmodel:mobile devices pscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2025-02725 // JVNDB: JVNDB-2021-016953 // NVD: CVE-2021-25516

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-25516
value: HIGH

Trust: 1.0

mobile.security@samsung.com: CVE-2021-25516
value: MEDIUM

Trust: 1.0

NVD: CVE-2021-25516
value: HIGH

Trust: 0.8

CNVD: CNVD-2025-02725
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-202112-655
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2021-25516
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2025-02725
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2021-25516
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

mobile.security@samsung.com: CVE-2021-25516
baseSeverity: MEDIUM
baseScore: 6.4
vectorString: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L
attackVector: ADJACENT
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: LOW
availabilityImpact: LOW
exploitabilityScore: 1.6
impactScore: 4.7
version: 3.1

Trust: 1.0

NVD: CVE-2021-25516
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2025-02725 // JVNDB: JVNDB-2021-016953 // CNNVD: CNNVD-202112-655 // NVD: CVE-2021-25516 // NVD: CVE-2021-25516

PROBLEMTYPE DATA

problemtype:CWE-703

Trust: 1.0

problemtype:CWE-755

Trust: 1.0

problemtype:Improper handling in exceptional conditions (CWE-755) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2021-016953 // NVD: CVE-2021-25516

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202112-655

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202112-655

PATCH

title:top pageurl:https://www.android.com/

Trust: 0.8

title:Patch for Samsung RRC MeasurementReport abnormal condition handling vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/354641

Trust: 0.6

title:Samsung SMR Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=174855

Trust: 0.6

sources: CNVD: CNVD-2025-02725 // JVNDB: JVNDB-2021-016953 // CNNVD: CNNVD-202112-655

EXTERNAL IDS

db:NVDid:CVE-2021-25516

Trust: 3.8

db:JVNDBid:JVNDB-2021-016953

Trust: 0.8

db:CNVDid:CNVD-2025-02725

Trust: 0.6

db:CNNVDid:CNNVD-202112-655

Trust: 0.6

sources: CNVD: CNVD-2025-02725 // JVNDB: JVNDB-2021-016953 // CNNVD: CNNVD-202112-655 // NVD: CVE-2021-25516

REFERENCES

url:https://security.samsungmobile.com/securityupdate.smsb?year=2021&month=12

Trust: 2.4

url:https://nvd.nist.gov/vuln/detail/cve-2021-25516

Trust: 2.0

sources: CNVD: CNVD-2025-02725 // JVNDB: JVNDB-2021-016953 // CNNVD: CNNVD-202112-655 // NVD: CVE-2021-25516

SOURCES

db:CNVDid:CNVD-2025-02725
db:JVNDBid:JVNDB-2021-016953
db:CNNVDid:CNNVD-202112-655
db:NVDid:CVE-2021-25516

LAST UPDATE DATE

2025-02-14T23:12:57.723000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-02725date:2025-02-12T00:00:00
db:JVNDBid:JVNDB-2021-016953date:2022-12-27T05:17:00
db:CNNVDid:CNNVD-202112-655date:2021-12-16T00:00:00
db:NVDid:CVE-2021-25516date:2021-12-13T17:55:34.503

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-02725date:2025-02-12T00:00:00
db:JVNDBid:JVNDB-2021-016953date:2022-12-27T00:00:00
db:CNNVDid:CNNVD-202112-655date:2021-12-08T00:00:00
db:NVDid:CVE-2021-25516date:2021-12-08T15:15:08.260